Position
IoT Technologies designs and manufactures monitoring hardware, firmware and cloud services in the United Kingdom.
We take reports of security vulnerabilities seriously, and we would rather hear from you than not.
Scope
This policy covers products and services designed and manufactured by IoT Technologies. That includes hardware supplied to partners and resold under their own brand names, our firmware, and our cloud platform.
If you are unsure whether a device is in scope, report it and we will tell you.
How to report
Email [email protected].
Please include the affected product or service, the conditions required to reproduce the issue, and what you observed.
Encrypted submission is available on request.
What we commit to
We will acknowledge your report within five working days of receipt.
We will give you a status update at least every twenty working days until the issue is resolved or closed.
We will tell you what we decide and why, including if we decide not to act.
We will not take legal action against researchers acting in good faith under this policy.
What we ask
Please give us reasonable time to investigate and remedy an issue before disclosing it publicly.
Please do not access, modify or delete data belonging to others, and please do not degrade the availability of live systems.
Testing should be limited to systems you own or have permission to test.
Partner and customer notification
Where a vulnerability affects deployed equipment, we notify affected customers and any partner supplying our hardware under their own brand name.
This is so that remediation reaches the organisations operating the equipment, not only the organisation that bought it.
No bounty
We do not currently operate a paid bug bounty.
We will credit reporters who wish to be named.
Company information
- Company
- IoT Technologies Ltd
- Registered in
- England and Wales
- Company number
- 14044861
- Registered office
- Venator House, Unit 9, 15-17 St Stephen's Road, Bournemouth, Dorset, BH2 6LA
- VAT number
- GB 409644484
This policy describes how IoT Technologies Ltd receives and handles vulnerability reports. It is not a warranty, a service commitment or a statement of certification.