Position
IoT Technologies designs and manufactures monitoring hardware, firmware and cloud services in the United Kingdom.
We take reports of security vulnerabilities seriously, and we would rather hear from you than not.
Scope
This policy covers products and services designed and manufactured by IoT Technologies. That includes hardware supplied to partners and resold under their own brand names, our firmware, and our cloud platform.
If you are unsure whether a device is in scope, report it and we will tell you.
Out of scope
The following are out of scope and receive no response:
- missing or misconfigured HTTP security headers
- email authentication observations (SPF, DKIM, DMARC)
- software or version disclosure
- clickjacking on pages with no sensitive actions
- absence of rate limiting
- self-XSS
- automated scanner output without a demonstrated impact
- best-practice recommendations without a demonstrated vulnerability
- issues in third-party services we use, which should be reported to that provider
Messages asking whether this address is monitored, or asking to agree terms or payment before disclosing, receive no response.
How to report
Email security@iottechnologies.co.uk.
Please include the affected product or service, the conditions required to reproduce the issue, and what you observed.
Encrypted submission is available on request.
What we commit to
We will acknowledge an in-scope report within five working days of receipt.
We will give you a status update at least every twenty working days until the issue is resolved or closed.
We will tell you what we decide and why, including if we decide not to act.
We will not take legal action against researchers acting in good faith under this policy.
What we ask
Please give us reasonable time to investigate and remedy an issue before disclosing it publicly.
Please do not access, modify or delete data belonging to others, and please do not degrade the availability of live systems.
Testing should be limited to systems you own or have permission to test.
Partner and customer notification
Where a vulnerability affects deployed equipment, we notify affected customers and any partner supplying our hardware under their own brand name.
This is so that remediation reaches the organisations operating the equipment, not only the organisation that bought it.
No bug bounty or rewards
IoT Technologies does not run a bug bounty programme and does not pay rewards, fees or gifts for vulnerability reports, whether requested before or after a report is made. We do not enter into payment discussions about reports.
We will credit reporters who wish to be named, for in-scope reports that lead to a fix.
Company information
- Company
- IoT Technologies Ltd
- Registered in
- England and Wales
- Company number
- 14044861
- Registered office
- Venator House, Unit 9, 15-17 St Stephen's Road, Bournemouth, Dorset, BH2 6LA
- VAT number
- GB 409644484
This policy describes how IoT Technologies Ltd receives and handles vulnerability reports. It is not a warranty, a service commitment or a statement of certification.