This policy applies to customer-managed deployments that you run in your own environment: private cloud, on-premises, and air-gapped installations. It does not cover the Overcut-hosted (SaaS) offering, which Overcut patches and operates directly.
1. Purpose & Scope
This policy defines how Overcut identifies, triages, remediates, and ships fixes for security vulnerabilities in the Overcut platform, and the support commitments for released versions. It applies to customer-managed deployments, including private cloud, on-premises, and air-gapped environments, and covers Overcut-developed application code and its dependencies. This policy does not cover vulnerabilities in customer-managed infrastructure, including databases, message buses, object storage, Kubernetes clusters, operating systems, networking components, or third-party systems integrated by the customer.2. Vulnerability Detection
Overcut continuously performs automated security analysis throughout the software development lifecycle.
Security findings are reviewed and triaged according to their severity and potential impact on customer environments.
Overcut supplements automated scanning with manual security reviews, external security assessments, and customer-reported findings.
3. Security Reporting
Security concerns, vulnerability disclosures, and suspected security issues may be reported tosupport@overcut.ai.
All reports are reviewed and processed through Overcut’s vulnerability management workflow.
4. Severity Classification
Vulnerabilities are classified using CVSS v3.1 base scores, adjusted where appropriate for exploitability, exposure, and impact within the Overcut platform.5. Remediation Timeframes
Remediation time is measured from the point a vulnerability is confirmed and triaged to the point a fix is made available in a released version.
Critical and High severity fixes may be released outside the regular release cycle and are backported to all supported versions within their support window.
6. Release Cadence
Overcut follows Semantic Versioning (MAJOR.MINOR.PATCH).- Feature (minor) releases are typically published every one to three months.
- Patch releases are published as needed to address defects and non-critical issues.
- Security releases may be published independently of the regular release schedule whenever a validated security fix is available.
7. Version Support & End-of-Life
Each Overcut release is supported for six months from its General Availability (GA) date. During the support period, Overcut provides:- Security patches
- Critical bug fixes
- Backported Critical and High severity security fixes
8. Patch Delivery
Fixes are delivered as versioned, immutable release artifacts.Kubernetes / Helm deployments
Customers apply updates using the corresponding released Helm chart version. Rollback can be performed by redeploying a previously released version.Docker Compose / standalone deployments
Customers apply updates by pulling and deploying the released container image versions associated with the target release.Air-gapped deployments
Customers may download released container images and deployment artifacts, transfer them into their internal environment, and publish them to their private registry. Updates and security patches can therefore be applied entirely within the customer network without requiring direct access to Overcut-hosted registries.9. Customer Notification
For security-relevant releases affecting customer-managed deployments, Overcut will:- Publish release notes describing relevant fixes and changes.
- Notify affected customers through established customer communication channels.
- Provide direct notification for Critical security issues together with recommended upgrade guidance where appropriate.
10. Policy Review
This policy is reviewed periodically and updated as Overcut’s products, security practices, and release processes evolve.This document describes Overcut’s current practices and version lifecycle commitments. Unless explicitly incorporated into a customer agreement, order form, or support agreement, it does not create contractual obligations and may be updated from time to time.