Responsible Disclosure Policy

Indusenz takes the security of our products seriously. If you believe you have found a security vulnerability in one of our products or services, we want to hear from you. This page describes how to report it and what you can expect from us.

This policy is our coordinated vulnerability disclosure (CVD) policy as required by the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

Scope

This policy applies to:

  • All hardware products manufactured by Indusenz
  • Firmware, software, cloud services and mobile apps that Indusenz provides as part of those products
  • indusenz.com and its subdomains

The following are out of scope:

  • Denial-of-service or volumetric attacks
  • Social engineering, phishing, or physical attacks against Indusenz staff or premises
  • Third-party services and websites we do not operate
  • Findings from automated scanners without a demonstrated impact
  • Missing security headers or best-practice recommendations without an exploitable weakness

How to report

Send your report by email to security@indusenz.com.

You can also find these details in machine-readable form at /.well-known/security.txt.

What to include

To help us reproduce and fix the issue quickly, please include:

  • The product, version, firmware or URL affected
  • A description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce it (proof-of-concept code, screenshots or logs are welcome)
  • Your name or handle and how you would like to be credited, if at all

Please report in English or Norwegian.

What you can expect from us

  • Acknowledgement of your report within 2 business days
  • An initial assessment of severity and validity within 10 business days
  • Regular status updates while we work on a fix, at least every 30 days
  • A fix or mitigation delivered as a free security update to affected users
  • Credit in our security advisory, if you wish

Coordinated disclosure

We ask that you give us a reasonable time to fix the issue before disclosing it publicly. Our default disclosure window is 90 days from the date we acknowledge your report, or sooner once a fix is available. We will agree a public disclosure date with you and publish an advisory at /advisories/.

If we determine that the vulnerability is being actively exploited, we may need to disclose earlier to protect users, and are legally required to notify the EU Agency for Cybersecurity (ENISA) and the relevant national authorities.

Safe harbour

We will not pursue legal action against researchers who:

  • Act in good faith and follow this policy
  • Avoid privacy violations, data destruction, and disruption of services
  • Do not access, modify or exfiltrate more data than is needed to demonstrate the vulnerability
  • Do not exploit the vulnerability beyond what is necessary to prove it exists
  • Give us reasonable time to respond before public disclosure

We consider research conducted in line with this policy to be authorized.

Bug bounty

Indusenz does not currently operate a paid bug bounty program. We do offer public acknowledgement and our sincere thanks.

Information security certification

Our information security management system is certified to ISO/IEC 27001:2023 by Nemko Scandinavia AS. The certification covers the development, production, sales and installation of our sensor networks, and the operation of the software that processes and stores the data they produce.

ISO/IEC 27001:2023

Information Security Management

Issued by:
Nemko Scandinavia AS
Certificate no.:
904119
Valid until:
View certificate  for ISO/IEC 27001:2023, Information Security Management

Contact


Policy version 1.0 — last updated 17 September 2026.