Legal
Vulnerability Disclosure Policy
DataRemote's policy for reporting security vulnerabilities in its products and services, including which systems may be tested, how to report a vulnerability, and the conditions under which DataRemote considers security research to be authorized.
Vulnerability Disclosure Policy
Last updated: August 5, 2026
Purpose
DataRemote, Inc. welcomes reports from security researchers and customers who believe they have identified a security vulnerability in a DataRemote product or service.
This policy describes which systems may be tested, how to report a vulnerability, and the conditions under which DataRemote considers security research to be authorized.
This is not a bug-bounty program. DataRemote does not currently offer monetary compensation for vulnerability reports unless agreed to in writing before testing begins.
Systems in scope
Good-faith security research is authorized for the following publicly accessible systems, provided the testing follows this policy:
https://dataremote.comhttps://static.dataremote.com- Other public systems that DataRemote identifies in writing as being in scope
Only components owned and operated by DataRemote are included. A DataRemote hostname, webpage, or product may contain integrations operated by another company; those third-party components are not automatically in scope.
DataRemote also accepts reports concerning its products, firmware, APIs, and the Ara device-management platform. However, active testing of those systems is authorized only when:
- You own or have explicit permission to test the affected device, account, and data;
- You are using a test environment expressly provided or approved by DataRemote; or
- DataRemote has provided written authorization for the specific testing.
If you are uncertain whether a system or activity is in scope, contact [email protected] before beginning your research.
Systems and activities not authorized
Unless DataRemote provides prior written authorization, this policy does not authorize testing of:
- Customer, reseller, distributor, partner, government, or carrier systems;
- Devices deployed at customer sites or in active field installations;
- Production Ara device-management infrastructure or another user’s account;
- Fire alarm, burglar alarm, elevator, emergency calling, E911, life-safety, or monitoring systems;
- Cellular networks, carrier infrastructure, SIM services, private APNs, or telecommunications networks;
- Microsoft 365, SendGrid, Cloudflare, Pipedrive, or other third-party platforms and services;
- DataRemote employees, contractors, offices, or physical facilities;
- Third-party integrations, even when accessible through a DataRemote webpage or hostname.
Vulnerabilities in third-party products should ordinarily be reported to the applicable provider. You may also notify DataRemote if the issue materially affects DataRemote or its customers.
The following activities are prohibited:
- Denial-of-service, distributed denial-of-service, load, or stress testing;
- Social engineering, phishing, impersonation, or physical intrusion;
- Password spraying, credential stuffing, or testing credentials obtained from a breach;
- Introducing malware, ransomware, persistent access, or destructive code;
- Accessing, copying, altering, deleting, or disclosing another person’s data;
- Intercepting communications or disrupting customer operations;
- Pivoting from an affected system to another system;
- Sending spam or unsolicited communications;
- Exploiting a vulnerability beyond the minimum necessary to demonstrate it;
- Automated scanning above two requests per second or continuing any testing that causes degradation;
- Any activity that violates applicable law or the rights of another person or organization.
Research guidelines
When performing authorized research, you must:
- Act in good faith and take reasonable steps to avoid harm;
- Use only accounts, devices, and information that you own or are authorized to use;
- Limit testing to the minimum necessary to confirm the vulnerability;
- Stop immediately if you encounter personal information, confidential information, credentials, customer data, or evidence of active compromise;
- Do not retain, transmit, or disclose data obtained unintentionally;
- Notify DataRemote promptly if a vulnerability presents an immediate risk to customers, public safety, or system availability;
- Preserve enough information to help DataRemote reproduce and correct the issue without collecting unnecessary sensitive data.
Reporting a vulnerability
Send vulnerability reports to:
Email: [email protected]
Suggested subject: [Security Report] Brief description
Please include, when available:
- The affected hostname, URL, product, model, firmware, application, or version;
- A description of the vulnerability and its potential impact;
- Clear reproduction steps;
- A minimal proof of concept, screenshots, or relevant logs;
- The date and approximate time the issue was observed;
- Whether you accessed any information unintentionally;
- Any recommended remediation;
- Your contact information and any coordinated-disclosure plans.
Do not send unnecessary personal information, customer data, private cryptographic keys, active credentials, or complete database contents. If ordinary email is unsuitable for supporting evidence, ask us to arrange a more appropriate transfer method.
What you can expect from DataRemote
For reports submitted in accordance with this policy, DataRemote intends to:
- Acknowledge receipt within three business days;
- Provide an initial assessment or request additional information within ten business days;
- Keep you reasonably informed about validated issues, generally at least once every fifteen business days while remediation is underway;
- Work with you to understand and reproduce the issue;
- Coordinate remediation and public disclosure where appropriate;
- Credit you publicly if you request recognition and DataRemote determines that disclosure is appropriate.
These are response targets rather than contractual service-level commitments. Remediation time will depend on severity, complexity, affected products, customer safety, third-party dependencies, and deployment requirements.
DataRemote may share a report with affected vendors, customers, carriers, regulators, or coordinating organizations when reasonably necessary to investigate or remediate the vulnerability.
Coordinated disclosure
Please keep vulnerability details confidential until DataRemote has corrected the issue or both parties have agreed on a disclosure date.
DataRemote generally aims to agree on a disclosure timeline of no more than 90 days. Additional time may be necessary for vulnerabilities involving safety-critical products, embedded devices, carrier dependencies, coordinated vendor fixes, or customer deployment cycles.
DataRemote will not require indefinite confidentiality. If we cannot agree on a timeline, we ask that you provide reasonable advance notice before publication so we can reduce risk to affected customers.
Safe harbor
When you conduct security research in good faith and comply with this policy, DataRemote will consider that research authorized and will not initiate legal action against you for the research.
If a third party initiates legal action relating to research that DataRemote determines complied with this policy, DataRemote may clarify that the research was conducted under this policy.
This safe harbor:
- Applies only to systems and activities that DataRemote has authority to authorize;
- Does not authorize access to third-party or customer systems;
- Does not waive the rights of any third party;
- Does not provide immunity from applicable law;
- Does not apply to conduct outside this policy.
If you are concerned that a planned activity may not be covered, contact [email protected] and obtain written authorization before proceeding.
No license or reward commitment
Submitting a report does not transfer ownership of your original research to DataRemote. You grant DataRemote permission to use the submitted information as necessary to investigate, reproduce, remediate, and coordinate disclosure of the vulnerability.
DataRemote does not promise payment, gifts, employment, or other compensation for reports unless expressly agreed to in writing in advance.
Policy changes
DataRemote may update this policy as its products and security program evolve. Changes apply prospectively from the date they are published.
Questions about this policy may be sent to [email protected].
Have a legal or compliance question?
Reach out to our team for licensing, warranty, or policy questions specific to your account.