Devialet media

DEVIALETVulnerability Policy Disclosure

This policy delineates the procedures and guidelines for Devialet concerning the investigation, identification, public disclosure, and resolution of common vulnerabilities and exposures impacting our products and services and that have been notified to Devialet. Devialet is dedicated to safeguarding the data and privacy of our clientele through the expeditious and effective management of vulnerability research. It is incumbent upon security researchers to adhere to this coordinated disclosure policy when identifying security vulnerabilities. This policy is applicable to entities that discover or disclose vulnerabilities in our products and is formulated based on and makes reference to methodologies outlined in ETSI 300 645 and ISO 29147:2018.

Terms and Conditions:

Under this policy, vulnerability research denotes activities wherein security researchers:

  • Notify Devialet promptly upon the discovery of any actual or potential security vulnerability.
  • Endeavor in good faith to prevent privacy infringements, uphold user experience, forestall disruptions to operational systems, and safeguard against data destruction or manipulation. Any security testing that contravenes the law may prompt criminal or legal scrutiny. Refer to the Legal Issues and Protections section.
  • Maintain the confidentiality of vulnerabilities during the coordinated disclosure timeframe of 90 calendar days, while affording Devialet a reasonable duration to rectify the issue before public disclosure.

Coverage of Vulnerabilities:

This policy encompasses all vulnerabilities within Devialet's interconnected products, platforms, and controlling mobile applications, including those in firmware, mobile applications, and cloud services.

Services not explicitly listed above, such as any connected services, are beyond the scope and are not sanctioned for testing by Devialet. Furthermore, vulnerabilities detected in systems from our providers lie outside the purview of this policy and should be directly reported to the respective provider in accordance with their disclosure policy (if any). Should uncertainty persist regarding a system’s inclusion in scope, please contact us. Security researchers should refer to the external vulnerability disclosure policies of any third-party interconnected service to ascertain the authorized testing scope of said services.

Devialetは、お客様から提供された情報を以下で定義された目的でのみ使用します。プライバシーポリシー
Devialet media