Introduction
Senceive is committed to the security of our products and services, including our remote monitoring hardware, firmware, and cloud/web platforms. We value the work of security researchers and the wider community in helping us keep our systems and our customers safe. This policy explains how to report a security vulnerability to us and what you can expect in return.
Scope
This policy applies to security vulnerabilities discovered in:
- Senceive hardware products and their firmware
- The Senceive cloud/web platform and associated web applications
- Senceive-owned websites and internet-facing services
If you are unsure whether something is in scope, please contact us and ask.
How to report a vulnerability
Please report suspected security vulnerabilities to us at:
- Reporting portal: https://helpdesk.senceive.com/
- Email: helpdesk@senceive.com
To help us assess and resolve the issue quickly, please include where possible:
- Please use the subject line "Security Vulnerability Disclosure", to help us route your report quickly
- A description of the vulnerability and its potential impact
- The product, firmware version, service, or URL affected
- Step-by-step instructions to reproduce the issue
- Any proof-of-concept code, screenshots, or logs
- Your contact details so we can follow up
If your report contains sensitive information, you may request an encrypted channel and we will provide one.
What we ask of you (responsible testing)
To protect our customers and systems, we ask that you:
- Give us a reasonable opportunity to investigate and remediate before disclosing any details publicly
- Do not access, modify, or delete data that does not belong to you
- Do not degrade, disrupt, or perform denial-of-service testing against our systems
- Do not use social engineering, phishing, or physical attacks against Senceive staff, customers, or facilities
- Act in good faith and comply with all applicable laws
What you can expect from us
- Acknowledgement: We will acknowledge receipt of your report within 5 working days.
- Assessment: We will investigate and validate the reported issue and keep you informed of our progress.
- Resolution: We will work to remediate confirmed vulnerabilities in a timeframe appropriate to their severity.
- Coordinated disclosure: We will coordinate any public disclosure with you and, where appropriate, credit you for your responsible report (unless you prefer to remain anonymous).
Last updated: 11-09-2026 · Version 1.0
