What the buyer is really asking
Cover the whole loop: how vulnerabilities are found, how they are ranked by severity, and how long each severity may stay open. Targets you actually meet are worth more than aggressive ones you miss.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you manage application vulnerabilities?”
- “What are your remediation timelines by severity?”
- “Do you have a vulnerability disclosure program?”
Evidence to have ready
- A vulnerability management policy with remediation targets
- Tracking records for recent findings
- A security.txt or disclosure page, if published
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.