Service-Disabled Veteran-Owned Small Business UEI NQ7DY8MADL23 CAGE 5AAG0 Registered in SAM.gov
New Vision Security Secure by design. Transparent by choice.
Security

Patch Policy

How fast we fix known vulnerabilities, and how we decide.

Draft for review. This page was prepared from company records and published practice. It has not been reviewed by counsel. Review and approve the wording before relying on it in a contract or a procurement response.

Timelines

Severity follows the Common Vulnerability Scoring System, adjusted for whether the component is actually reachable in our deployment. A critical score in a library we do not call is not a critical risk, and we document that reasoning rather than ignoring the finding.

SeverityCVSSRemediation target
Critical9.0 to 10.07 calendar days
High7.0 to 8.930 calendar days
Medium4.0 to 6.990 calendar days
Low0.1 to 3.9Next scheduled maintenance

Scope

  • Application dependencies and runtime packages
  • Container and virtual machine images we build
  • Configuration of the managed Azure services we operate

Patching of the underlying Azure platform is Microsoft's responsibility under the shared responsibility model.

Emergency changes

A vulnerability under active exploitation is patched as fast as a safe deployment allows, without waiting for a maintenance window. Customers are notified if the change affects availability.

Exceptions

Where a fix cannot be applied within target, the exception is recorded with the reason, the compensating control, and a review date. Exceptions are time-limited.