Legal & Compliance Notice
Covers China / US / EU jurisdictions · Active compliance moat
1. China — Network Product Security Vulnerability Management Regulations
vulnti.work aggregates only vulnerability metadata that has already been publicly disclosed by whitelisted sources (NVD / GHSA / CISA KEV / CNNVD / CNVD / vendor PSIRT, etc.) and adds AI-localized Chinese analysis and actionable triage. The site complies with the PRC Network Product Security Vulnerability Management Regulations (jointly issued by MIIT, CAC, and MPS; effective 2021-09-01): (1) no dissemination of undisclosed vulnerability leads (patch-diff back-inference, private mailing-list pre-disclosure, private channels, dark-web intelligence); (2) no publication of unfixed attack methods or executable PoC details; (3) entries are updated or retracted within 48 hours of receiving a CNNVD / CNVD / vendor notification; (4) every entry is reverse-verifiable through the public channels enumerated on /sources. The site therefore does not engage in "vulnerability disclosure" within the meaning of Article 9 of those Regulations — it performs Chinese-localized aggregation of already-public information.
2. US Export Control (EAR Category 5 Part 2)
Content is published strictly for defensive and research purposes. No working exploit payloads are provided. ExploitDB-class data references metadata only and links externally to the original source; executable dual-use exploit code is not mirrored. The site does not constitute the export of dual-use technology under EAR Category 5 Part 2.
3. EU GDPR
The platform does not maintain subscriber profile data. Webhook URLs are stored AES-GCM encrypted; email subscription addresses are hashed and AES-GCM encrypted; we perform no behavioural profiling or cross-device tracking. Subscriber-side filters (product / CPE / severity) travel with the subscription token and are not persisted server-side. The site sets no tracking cookies, integrates no third-party analytics SaaS (Google Analytics / Umeng / Baidu Tongji and the like), and embeds no third-party advertising or social-network scripts. Anonymous access logs retain only Cloudflare edge defaults for security purposes. See Constitution C-08.
4. CH-4 Social-Channel Fair-Use Stance
WeChat 公众号 quotation rule: ≤300-char Chinese summary + ≤200-char verbatim key-passage quotation + outbound link + mandatory attribution ("Original: account · title · author · publish time"), per Article 24 of the PRC Copyright Law. Full-text mirroring, removal of the original advertisements / disclaimers, and derivative rewriting are forbidden. Twitter / X quotation rule: per-tweet ≤280 characters (the platform native limit) + @username attribution + outbound link to the original tweet + NO use of the official Twitter embed widget (to avoid leaking visitor IP / cookies back to Twitter, consistent with §3). This follows the four-factor US fair-use analysis (research, non-commercial, transformative quotation, no substantive substitution). CH-4 content defaults to the auto channel and is rendered with an explicit AI quality-classifier confidence label. If the original author or publishing account objects, contact the operator through the channels in §7.
5. Liability & Disclaimer
Detailed scope of liability and limitations is set out on the /disclaimer page.
6. Copyright & Licensing Boundary
The vulnti.work site code (Astro / Workers / D1 schema / docs) is released under the MIT License, anonymously published by the operator. Site content carries two distinct copyright layers: (1) vulnerability metadata is sourced from upstream public publishers (NVD / GHSA / CISA KEV / CNNVD / CNVD / vendor PSIRT / mailing lists); copyright remains with the original publishers and vulnti.work claims no ownership of the metadata itself. (2) vulnti.work holds compilation-copyright over its aggregation method, AI-localised Chinese summaries, triage text, and dual-channel publication judgement; downstream subscribers may freely quote and mirror this layer provided they retain source attribution, the outbound link, do not commercialise derivative works, and do not strip the `legal_notice` field (equivalent to a CC BY-NC-SA 4.0 stance; the formal LICENSE file ships with the Phase 1A open-source repository). Every RSS / Webhook / Email payload mandatorily carries the `legal_notice` URL (per DR-006 / C-02) and that field must not be removed by downstream integrators.
7. Retraction, Takedown & Dispute Channels
Per Constitution C-03, the project operates anonymously and provides no named customer-service or phone line. The following anonymous channels are the only inbound contact: (1) **Takedown requests** — copyright holders / regulators / vendor PSIRTs / original authors should submit via the GitHub Issues template at https://github.com/vulnti/vulnti/issues/new?template=legal-takedown.md (response within 48h). Please include: the affected vuln_id or URL, the basis of claim (copyright / factual error / regulatory notice), and a verifiable identity proof (corporate-domain email, regulatory document number, or PSIRT official-page link). (2) **Factual correction** — readers reporting a false positive or factual error use the same template with subject-line prefix `[INACCURATE]` plus supporting evidence. Maximum response window: **48 hours** (aligned with the 48-hour mechanism in Article 9 of the PRC Network Product Security Vulnerability Management Regulations); urgent regulatory notices take priority. The outcome (takedown, revision, or maintain) is in every case published on /retractions with a stated reason. **Governing law**: the site is hosted on Cloudflare's global edge with an anonymous operator. Disputes are governed primarily by the publisher-of-record jurisdiction of the disputed content; absent that, the PRC Network Product Security Vulnerability Management Regulations, PRC Copyright Law, and US DMCA fair-use provisions apply as fallback references.