I — Purpose
This Coordinated Vulnerability Disclosure Policy (VDP) describes the procedure for anyone to responsibly report a security vulnerability that may affect products or services offered by REVAME.
II — Products concerned
- Multi-zone and multi-purpose controllers (Room Controllers)
- Communication gateways
- Associated cloud services
- Associated mobile applications
- Web configuration and supervision interfaces
- Any software or firmware developed by REVAME
III — Security contact
Vulnerabilities must be reported using the dedicated online form at the following address: security.revame.com/vdisclose
The following information is requested:
- detailed description of the vulnerability
- affected product
- firmware or software version
- estimated impact
- reproduction method
- reporter contact details
IV — Company commitment
- acknowledge receipt of the report within a maximum of 5 business days
- analyze the vulnerability
- maintain dialogue with the reporter
- assess the impact on our products
- implement appropriate corrective actions
- inform affected users when necessary
V — Conditions applicable to security research
REVAME products are primarily deployed in buildings operated by customers or third parties. To preserve the security and availability of these installations:
- no testing must be performed on equipment operated by customers or third parties
- no attempt to gain unauthorized access may be made
- no service interruption may be caused
- no data belonging to a customer or third party may be accessed, modified or copied
- analysis must be limited to equipment legally owned by the reporter or explicitly made available for research purposes
VI — Authorized activities
The following activities are authorized when strictly limited to demonstrating the vulnerability:
- communication protocol analysis
- reasonable robustness testing
- authentication verification
- analysis of legally obtained software
- analysis of exposed interfaces
VII — Prohibited activities
- intentional service interruption
- denial of service (DoS or DDoS)
- destruction or alteration of data
- access to third-party data
- compromise of customer systems
- propagation of malicious software
- persistent exploitation of a vulnerability after it has been demonstrated
VIII — Coordinated disclosure
- do not publicly disclose a vulnerability before a fix is available or mutual agreement has been reached
- allow us a reasonable period to analyze and correct the issue
- report vulnerabilities exclusively through the channels described in this policy
After remediation, we may publish a security advisory describing:
- affected products
- affected versions
- corrective measures
- any credits given to the reporter
IX — Safe Harbor
If a researcher acts in good faith, complies with this policy, does not seek to access third-party data and does not disrupt the normal operation of systems, REVAME will not seek legal action against the researcher for activities strictly necessary to identify and report the vulnerability.
X — Personal data processing
Information submitted as part of a vulnerability report is used only to:
- analyze the vulnerability
- communicate with the reporter
- meet any regulatory obligations
This information is processed in accordance with our privacy policy.