Effective September 9th, 2026, esaqa GmbH is a CVE Numbering Authority (CNA) operating under the ENISA Root. This allows us to assign CVE Identifiers (CVE IDs) and publish CVE Records for eligible vulnerabilities within our scope, including vulnerabilities affecting products developed and maintained by esaqa GmbH, such as Psono.
Joining the global CVE Program is an important step in the continued development of our vulnerability-management processes. It gives researchers, customers, vendors, and defenders a consistent way to identify and discuss publicly disclosed vulnerabilities in our products.
The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. Each qualifying vulnerability receives a unique CVE ID and a corresponding CVE Record. These records provide a shared reference that security teams, software vendors, vulnerability scanners, and public databases can use when discussing and addressing the same issue.
CNAs are organizations authorized by the CVE Program to assign CVE IDs and publish CVE Records for vulnerabilities within an agreed scope. As a CNA, esaqa GmbH can now manage this process directly where we have assignment authority. Our responsibilities include:
Our CNA status creates a more direct path from a confirmed vulnerability report to a globally recognized identifier and public record. When a vulnerability in scope requires an identifier, we no longer need to rely on another CNA to assign its CVE ID.
This should make our vulnerability-handling process more consistent and help us communicate advisories, affected versions, fixes, and mitigations clearly and effectively. It also makes it easier for customers and security tools to track an issue across release notes, advisories, scanners, and vulnerability databases.
Becoming a CNA does not mean that vulnerabilities cannot occur, and a CVE ID is not a severity rating or security certification. It means that we are taking direct responsibility for transparent, timely, and coordinated handling of eligible vulnerabilities in our scope.
ENISA, the European Union Agency for Cybersecurity, became a CVE Root for European entities in November 2025. In this role, ENISA recruits, trains, supports, and manages CNAs within its scope while helping ensure that CVE Program rules and processes are followed.
Operating under the ENISA Root connects our work to a growing European vulnerability-management ecosystem while remaining part of the shared global CVE Program. We appreciate ENISA's guidance and support throughout the onboarding process.
We welcome reports from security researchers, customers, partners, and other members of the security community. If you believe you have found a vulnerability in Psono or another product or service developed or maintained by esaqa GmbH, please review our Vulnerability Disclosure Policy and contact security@esaqa.com.
Reports may be submitted in English or German. Sensitive reports can be encrypted using the OpenPGP key referenced in our security.txt file. Please include the affected product and version, a clear description of the issue and its impact, and reproduction steps or a proof of concept where possible.
Our CNA responsibilities build on the security practices we already follow: coordinated vulnerability disclosure, regular independent security audits, open-source transparency, and clear communication with our users. We look forward to contributing more directly to the CVE Program and the wider cybersecurity community.