Proof
We do this to ourselves first
The component list, disclosure policy and paperwork of our own product, produced by the pipeline we sell and republished on every release.
Updated 7 September 2026
Anyone can say they do this
So here is ours. Everything below comes from our own product, produced by the same work we sell you, and published so you can look at it before you ever speak to us.
It is proof that we practise what we sell, not a certificate. Publishing our paperwork does not make our product compliant, and it would not make yours compliant either. It shows you what these deliverables look like when they are real.
It is also the honest answer to "what am I left with?". A small firm that finishes this work is left running roughly what you see below, out of its own build and its own repository. Two engineers keep ours going in the gaps of a working week. If it needed a department, we would not have one either.
What you are about to see
The current release, then the list of every component our own product is built from, with the moment it was generated and a checksum so you can tell it has not been altered. Then the policy that tells outsiders how to report a security problem to us, and the file on our website that points them to it. Then our paperwork folder, section by section, with the evidence attached to each one — and the sections that have none still marked as empty, because hiding them would defeat the point.
The manufacturer draws up the technical documentation with the content set out in Annex VII before placing the product on the market and keeps it up to date during the support period.[Art. 31; Annex VII]Nothing here is pasted in by hand. It is fetched from our platform.
Our own evidence, published
Shown from the copy taken from our platform on 7 September 2026 (build a0f3211d4ed6); the platform was not reachable when this page was built.
The release you are looking at
- Version
- a83e949
- Build
- a83e9494201d
- Built
- 7 September 2026 03:52 UTC
What our product is made of
811
software components in this release
- Format
- CycloneDX
- Generated
- 7 September 2026 03:52 UTC
- SHA-256
- e50f125f41566b9e60bfb947c82a72f186761034d2d3281cde6e03b203313c46
What our own scan found
Last scan: 7 September 2026 03:52 UTC
- 3red
- 10amber
- 2green
Red: a weakness attackers are using, a critical finding, or a leaked secret. Amber: serious but not under attack. Green: minor.
Our paperwork folder
- General description of the productpartialnothing attached yet
- Design, development, production and vulnerability handlingpartial
10 attached — show the checksums
- Generated Tier 3 document 386346cd60f25b97c119f33fa96123f9e9a848938ffd0c165cf655b083a29969
- Generated Tier 3 document 84b91aa5a51d328da3bb41d49d028d4199bee19679c1ef30255cd0c04ea689c7
- Generated Tier 3 document 9f0917b557e96991a8faa3d37526e75548b8424ced26ab360da4003d3512ff88
- Generated Tier 3 document fa5695bb94f0ce396bfd09b786d1b2f7fd83b0f541513b016d6adc5ff77b64d4
- Generated Tier 3 document b67f617af0b66bfc3614fa2d530cdd68ffcc848650e61f342dc2f56bd0b4e76b
- Generated Tier 3 document ac6b4f298f97263d2ebf2620500f7920fdbafe83a407878f1e383eeeb5e47353
- Generated Tier 3 document f47f45430c44049015c31df53798fa73b0dfd6e939b81d273f21ce69939d4aee
- Generated Tier 3 document 164cafcd3aea420d84ea72238e7e76ce58101fa8a34cd5d3797af06c435d0a48
- Generated Tier 3 document 749e5114e3ac8b73ee6408c39c339d54707089e48525230da03cb79d9e4d8d99
- Generated Tier 3 document 23f278ab03eaafc21c630c4e581dfbc2a92d898e50ff6249b4a86dd9ea7bc5f4
- Cybersecurity risk assessmentmissingnothing attached yet
- Support period determinationpartial
1 attached — show the checksums
- Scoping memorandum fb10939d26826a3ecb66a60657d4438b1c510bc1bfb99cc385dbc1ae3583a4e8
- Standards and specifications appliedpartialnothing attached yet
- Test reportspartial
2 attached — show the checksums
- Normalised findings 1e4f0fe5618fe51662ff5858fa943cf1b30f703812c87b8991353fd2c2c2076a
- Gap report ec7d2727694f75e76c8108139c4b42ab7af033f50e97e52a1e7bbbd0e91bad4d
- Copy of the EU declaration of conformitymissingnothing attached yet
- Software bill of materialscomplete
1 attached — show the checksums
- Software bill of materials (CycloneDX) e50f125f41566b9e60bfb947c82a72f186761034d2d3281cde6e03b203313c46
How to report a security problem to usRead it
Coordinated vulnerability disclosure policy — DASKALOS APPS SAS
Effective from 6 September 2026 · version 1.0
1. Purpose
DASKALOS APPS SAS welcomes reports of security vulnerabilities in its products and services. This policy explains what is in scope, how to report, what we promise in return, and how we work with reporters towards coordinated disclosure.
2. Scope
This policy covers:
- SentinelSphere CRA 0.2.0-dev and all supported versions
The following are out of scope of this policy:
- Social engineering, phishing or physical attacks against our staff, offices or users.
- Denial-of-service testing or any activity that degrades the service for others.
- Findings in third-party services we do not operate; report those to the third party.
- Reports produced only by automated scanners without a demonstrated impact.
- Issues in versions no longer supported (see our support period statement).
3. How to report
Send your report through one of these channels:
- Email: security@cra.example.test
- Languages we read: English, French, Greek
Please include, as far as you can:
- The product, version and component affected.
- Steps to reproduce, or a proof of concept that does not damage data.
- The impact you believe the issue has.
- Whether you have shared the finding with anyone else, and how we may credit you.
4. What we promise
- We acknowledge your report within the time stated below and give you a tracking reference.
- We triage the report, tell you our severity assessment and keep you informed of progress.
- We do not take legal action against reporters who follow this policy (see Safe harbour).
- We fix confirmed vulnerabilities within the target below and deliver the fix through our documented update channel.
- We tell you when the fix is released and coordinate the publication of an advisory with you.
- We handle your personal data only to process the report.
5. Timelines
| Step | Target |
|---|---|
| Acknowledgement of receipt | 3 business days |
| Triage and initial assessment | 10 business days |
| Target for a fix or mitigation | 90 calendar days |
| Default coordinated disclosure period | 90 calendar days |
Targets are counted in business days (Monday to Friday, excluding public holidays at our registered office) or calendar days as stated. Complex issues may need longer; we will tell you why and agree a new date with you.
6. Safe harbour
DASKALOS APPS SAS considers security research conducted under this policy to be authorised and conducted in good faith, provided that you:
- Do not access, modify or delete data beyond what is needed to demonstrate the issue.
- Do not disrupt the service or degrade it for other users.
- Do not use the issue to move to other systems or persist access.
- Stop testing and report immediately if you encounter personal data or confidential information.
- Do not publish the vulnerability before the coordinated disclosure date agreed with us.
- Comply with the law of your country and ours.
If a third party starts legal action against you for research conducted under this policy, we will make it known that your actions were conducted in accordance with it. This policy cannot bind third parties or authorities.
7. Coordinated disclosure
We aim to publish an advisory within 90 calendar days of the report, or earlier once a fix is available. We request CVE identifiers for confirmed vulnerabilities in our products, we notify national authorities where the law requires it, and we agree the publication date with you. Where a fix needs longer, we will propose a new date and explain why.
8. Credit
We credit reporters who wish to be named in our advisory and, with their consent, on our acknowledgements page. Tell us in your report how you would like to be credited, or if you prefer to remain anonymous.
We do not operate a bug bounty programme and do not pay for reports.
9. security.txt
Our contact details, this policy and the expiry date of this information are published in a machine-readable security.txt file at https://cra.example.test/.well-known/security.txt, following RFC 9116.
10. Changes to this policy
DASKALOS APPS SAS may update this policy. The version number and effective date at the top identify the current version; earlier versions are kept on request.
Published by DASKALOS APPS SAS as part of its vulnerability handling under Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements (the Cyber Resilience Act).. Reports are handled according to our vulnerability handling procedure.
security.txtShow the file
Served at /.well-known/security.txt
# security.txt for DASKALOS APPS SAS — how to report a vulnerability (RFC 9116) # Generated on 6 September 2026; keep the Expires field within one year. Contact: mailto:security@cra.example.test Expires: 2027-09-06T00:00:00.000Z Preferred-Languages: en, fr, el Canonical: https://cra.example.test/.well-known/security.txt Policy: https://cra.example.test/security
The rules, facts and prices on this site come from our platform build a0f3211d4ed6 (7 September 2026).
How it stays honest
A job regenerates every item on this page on each release. A test fails our build if what you see here is older than our latest release. If you ever find a stale date, that is a bug, and we would rather hear about it — the security page says how.
What happened when we ran it on ourselves
We put our own platform through the whole thing — scoping, scanning, the gap report, the sprint — before selling any of it to anyone. This is what that cost and what it taught us.
What we ran
[WRITE-UP: WHICH REPOSITORIES, WHICH SCANNERS, WHEN]
What we found
[WRITE-UP: WHAT THE SCAN TURNED UP, AND WHAT SURPRISED US]
What we changed
[WRITE-UP: THE CODE CHANGES, THE POLICIES, THE PLAN]
What we would do differently
[WRITE-UP: TEMPLATE FIXES, TIME SPENT AGAINST BUDGET]
Talk to an engineer
You have seen our own evidence. Ask us what yours would look like.