Hi Dan,

Thanks.

Arm PSIRT, could you please advise on the questions in my original message below?

Regards,
Guled

On Wednesday, 2 September 2026 at 12:07 PM, Dan Handley <Dan.Handley@arm.com> wrote:
(+ Arm PSIRT)

Hi Guled

I think your question is best directed to Arm PSIRT, since it is Arm that runs this bug bounty program, not Trusted Firmware.

Regards

Dan.

From: anarchy via TSC <tsc@lists.trustedfirmware.org>
Date: Wednesday, 2 September 2026 at 11:56
To: tsc@lists.trustedfirmware.org <tsc@lists.trustedfirmware.org>
Subject: [TF-TSC] Clarification on duplicate handling during Intigriti triage

I would like clarification on how the Trusted Firmware bug bounty program handles researcher priority when submissions remain with Intigriti for an extended triage period.

Intigriti triage can currently take approximately one to two months. During that period, it is possible for Arm or the Trusted Firmware project to independently discover, investigate, or fix the same vulnerability before Intigriti completes triage and forwards the submission.

In that situation, what point in time is used to determine whether a report is considered “already known” or a duplicate?

Specifically, is priority determined using the researcher’s original submission timestamp, or the later date on which Intigriti completes triage and the report reaches Arm?

If a researcher submits a vulnerability first, but Arm independently discovers or fixes the same issue while that submission is still awaiting Intigriti triage, does the researcher retain priority and bounty eligibility?

Conversely, if Arm considers the issue to have already been known before the researcher submitted it, what timestamp or internal record is used to establish that the issue predates the submission?

Finally, does Arm PSIRT or the Trusted Firmware security team receive any information about submissions while they are still in Intigriti’s Triage state, or are reports only passed to Arm after Intigriti completes triage.

Best regards,
Guled