Introduction

Wirepas is committed to maintaining the security of its products. Responsible, coordinated vulnerability disclosure helps protect our customers, partners, and ecosystem, and we welcome reports from security researchers, customers, and any other party who discovers a potential security vulnerability in a Wirepas product.

This page describes how security vulnerabilities in Wirepas products may be reported, how Wirepas handles such reports, and how and when Wirepas discloses information about resolved vulnerabilities.

Scope

This policy applies to security vulnerabilities in products developed and supported by Wirepas.

Where a reported issue involves third-party components or dependencies, Wirepas will assess and coordinate handling to the extent the issue is caused or materially affected by Wirepas products.

Reporting Channels

Security vulnerabilities should be reported through one of the following channels:

  • Wirepas Developer Portal (developer.wirepas.com) — the preferred channel for Wirepas licensees, as it enables structured submission and streamlined communication.

  • Email: security@wirepas.com — publicly available and should be used by security researchers and other external parties, or when portal access is not available.

Both channels support two-way communication between Wirepas and the reporter throughout the vulnerability assessment and handling process.

Reporting a Vulnerability

We encourage anyone who discovers a potential security vulnerability in a Wirepas product to report it to us as soon as possible.

Reports should include sufficient detail to allow reproduction and assessment of the issue, such as:

  • High-level description of the vulnerability along with its potential impact

  • Affected product, component and version

  • Detailed description of the reproduction steps for the potential vulnerability

  • Any relevant contextual supporting information, such as logs, crash dumps, or screenshots, where available

Wirepas will use the provided contact information to maintain two-way communication with the reporter during assessment and coordination.

Reporter Expectations

Reporters are expected to:

  • Act in good faith and avoid privacy violations, data destruction, or service disruption

  • Not exploit vulnerabilities beyond what is necessary to demonstrate their existence

  • Allow reasonable time for investigation and remediation efforts

  • Refrain from publicly disclosing details of the vulnerability until a fix or mitigation is available and disclosure timing has been coordinated with Wirepas

Secure Communication

Where sensitive technical details are involved, Wirepas may propose the use of secure communication channels for continued handling of the report.

Company Commitments

Upon receiving a vulnerability report, Wirepas will:

  • Acknowledge receipt of the report within five (5) business days

  • Assign a tracking reference to each vulnerability report to support follow-up and communication

  • Assess and validate the reported vulnerability

  • Request additional information from the reporter where needed

  • Determine severity and potential impact

  • Determine appropriate remediation or mitigation measures, where feasible

  • Maintain ongoing communication with the reporter during verification and handling

  • Coordinate disclosure timing with the reporter where practical

  • Inform the reporter of the outcome of the vulnerability verification, subject to confidentiality and security considerations

The availability and timing of remediation actions may depend on factors including product lifecycle stage, technical feasibility, and upstream dependency constraints.

Disclosure and Communication

Confirmed vulnerabilities may be publicly disclosed via the Wirepas Developer Portal, in accordance with this policy, once remediation, mitigations, or other appropriate risk-reducing measures are available.

Wirepas will assign vulnerability identifiers and disclose security advisories to affected customers and licensees, including information on affected products and versions, severity, potential impact, and recommended remediation steps.

Disclosure may take the form of early customer notification, security advisories, release notes, documentation updates, or other customer communications, depending on severity and impact. Where vulnerabilities affect multiple stakeholders, Wirepas may coordinate disclosure with customers, partners, or relevant third parties to support responsible and timely handling.

Out of Scope

The following are generally considered out of scope:

  • Issues requiring physical access without prior authorization

  • Social engineering attacks

  • Denial-of-service attacks

  • Vulnerabilities in third-party systems not under Wirepas control, where the issue is neither caused nor made worse by Wirepas products and cannot be reasonably mitigated by Wirepas

Non-Contractual Nature

This Coordinated Vulnerability Disclosure Policy is informational and non-contractual. Product support, remediation scope, service levels, and security obligations are governed by applicable customer agreements and product documentation.

Policy Updates

This policy may be updated periodically to reflect changes in legal, regulatory, or operational requirements. The latest version will be published on Wirepas public documentation channels.

Revision History

Version

Date

Summary

1

2026-09-10

Initial version.

Confidentiality: public