Responsible Disclosure Policy
Indusenz takes the security of our products seriously. If you believe you have found a security vulnerability in one of our products or services, we want to hear from you. This page describes how to report it and what you can expect from us.
This policy is our coordinated vulnerability disclosure (CVD) policy as required by the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
Scope
This policy applies to:
- All hardware products manufactured by Indusenz
- Firmware, software, cloud services and mobile apps that Indusenz provides as part of those products
- indusenz.com and its subdomains
The following are out of scope:
- Denial-of-service or volumetric attacks
- Social engineering, phishing, or physical attacks against Indusenz staff or premises
- Third-party services and websites we do not operate
- Findings from automated scanners without a demonstrated impact
- Missing security headers or best-practice recommendations without an exploitable weakness
How to report
Send your report by email to security@indusenz.com.
You can also find these details in machine-readable form at /.well-known/security.txt.
What to include
To help us reproduce and fix the issue quickly, please include:
- The product, version, firmware or URL affected
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce it (proof-of-concept code, screenshots or logs are welcome)
- Your name or handle and how you would like to be credited, if at all
Please report in English or Norwegian.
What you can expect from us
- Acknowledgement of your report within 2 business days
- An initial assessment of severity and validity within 10 business days
- Regular status updates while we work on a fix, at least every 30 days
- A fix or mitigation delivered as a free security update to affected users
- Credit in our security advisory, if you wish
Coordinated disclosure
We ask that you give us a reasonable time to fix the issue before disclosing it publicly. Our default disclosure window is 90 days from the date we acknowledge your report, or sooner once a fix is available. We will agree a public disclosure date with you and publish an advisory at /advisories/.
If we determine that the vulnerability is being actively exploited, we may need to disclose earlier to protect users, and are legally required to notify the EU Agency for Cybersecurity (ENISA) and the relevant national authorities.
Safe harbour
We will not pursue legal action against researchers who:
- Act in good faith and follow this policy
- Avoid privacy violations, data destruction, and disruption of services
- Do not access, modify or exfiltrate more data than is needed to demonstrate the vulnerability
- Do not exploit the vulnerability beyond what is necessary to prove it exists
- Give us reasonable time to respond before public disclosure
We consider research conducted in line with this policy to be authorized.
Bug bounty
Indusenz does not currently operate a paid bug bounty program. We do offer public acknowledgement and our sincere thanks.
Information security certification
Our information security management system is certified to ISO/IEC 27001:2023 by Nemko Scandinavia AS. The certification covers the development, production, sales and installation of our sensor networks, and the operation of the software that processes and stores the data they produce.
Information Security Management
- Issued by:
- Nemko Scandinavia AS
- Certificate no.:
- 904119
- Valid until:
Contact
- Security reports: security@indusenz.com
- General enquiries: mail@indusenz.com
Policy version 1.0 — last updated 17 September 2026.
