Product security

Report a Product Security Vulnerability

This page explains how to report a suspected security vulnerability affecting a Blusafe smart lock, associated application, firmware or connected service.

How to report a security issue

Email our monitored security contact

Report a vulnerability

Please include, where available:

  • the Blusafe product model;
  • the product serial number, QR code or batch information;
  • the relevant application and firmware version;
  • a clear description of the suspected security issue and its possible impact;
  • safe steps that allow us to reproduce the issue; and
  • relevant screenshots, logs or other evidence.

Do not send passwords, access codes, live customer credentials or unnecessary personal information.

Providing your name is optional. An email address or another reply route is only needed if you would like to receive acknowledgements and status updates about your report.

What happens after a report

  • AcknowledgementWithin 2 working days
  • First status updateWithin 10 working days
  • Further updatesAt least every 20 working days until the issue is resolved or closed

The time needed to investigate and correct an issue depends on its severity and complexity. We may ask you for additional technical information where necessary.

Responsible reporting

When investigating a suspected issue, please do not:

  • break applicable law;
  • access data that does not belong to you;
  • alter or delete data;
  • disrupt a product or service;
  • perform denial-of-service testing;
  • use destructive or unnecessarily intrusive testing; or
  • publicly disclose an unresolved issue in a way that could put customers at risk.

Scope

This reporting route covers security issues affecting Blusafe relevant connectable products and their associated software or services.

For installation advice, order enquiries, returns and ordinary product faults, please use our normal customer-support channels instead.