SECURITY

Coordinated Vulnerability Disclosure Policy

Our objective is to protect our customers, partners and users by encouraging the identification, analysis and prompt remediation of security vulnerabilities.

I — Purpose

This Coordinated Vulnerability Disclosure Policy (VDP) describes the procedure for anyone to responsibly report a security vulnerability that may affect products or services offered by REVAME.

II — Products concerned

  • Multi-zone and multi-purpose controllers (Room Controllers)
  • Communication gateways
  • Associated cloud services
  • Associated mobile applications
  • Web configuration and supervision interfaces
  • Any software or firmware developed by REVAME

III — Security contact

Vulnerabilities must be reported using the dedicated online form at the following address: security.revame.com/vdisclose

The following information is requested:

  • detailed description of the vulnerability
  • affected product
  • firmware or software version
  • estimated impact
  • reproduction method
  • reporter contact details

IV — Company commitment

  • acknowledge receipt of the report within a maximum of 5 business days
  • analyze the vulnerability
  • maintain dialogue with the reporter
  • assess the impact on our products
  • implement appropriate corrective actions
  • inform affected users when necessary

V — Conditions applicable to security research

REVAME products are primarily deployed in buildings operated by customers or third parties. To preserve the security and availability of these installations:

  • no testing must be performed on equipment operated by customers or third parties
  • no attempt to gain unauthorized access may be made
  • no service interruption may be caused
  • no data belonging to a customer or third party may be accessed, modified or copied
  • analysis must be limited to equipment legally owned by the reporter or explicitly made available for research purposes

VI — Authorized activities

The following activities are authorized when strictly limited to demonstrating the vulnerability:

  • communication protocol analysis
  • reasonable robustness testing
  • authentication verification
  • analysis of legally obtained software
  • analysis of exposed interfaces

VII — Prohibited activities

  • intentional service interruption
  • denial of service (DoS or DDoS)
  • destruction or alteration of data
  • access to third-party data
  • compromise of customer systems
  • propagation of malicious software
  • persistent exploitation of a vulnerability after it has been demonstrated

VIII — Coordinated disclosure

  • do not publicly disclose a vulnerability before a fix is available or mutual agreement has been reached
  • allow us a reasonable period to analyze and correct the issue
  • report vulnerabilities exclusively through the channels described in this policy

After remediation, we may publish a security advisory describing:

  • affected products
  • affected versions
  • corrective measures
  • any credits given to the reporter

IX — Safe Harbor

If a researcher acts in good faith, complies with this policy, does not seek to access third-party data and does not disrupt the normal operation of systems, REVAME will not seek legal action against the researcher for activities strictly necessary to identify and report the vulnerability.

X — Personal data processing

Information submitted as part of a vulnerability report is used only to:

  • analyze the vulnerability
  • communicate with the reporter
  • meet any regulatory obligations

This information is processed in accordance with our privacy policy.