Our Commitment
Grid Connect welcomes reports from security researchers, customers, and partners about potential vulnerabilities in our products. We investigate all good-faith reports, we fix what needs fixing, and we credit those who help us protect our users.
How To Report
- Fill out the form below. Include the product model and firmware version, a description of the issue, steps to reproduce or proof of concept, and how we can reach you.
- If your report contains sensitive exploit details, email security@gridconnect.com to ask for a secure transfer method and we will provide one.
What We Promise
- Acknowledgement of your report within 3 business days.
- A point of contact and status updates at least every 2 weeks while we investigate.
- A remediation target based on severity; we aim to release fixes for confirmed critical issues within 30 days and to complete coordinated disclosure within 90 days of your report unless we otherwise agree on a different timeline.
- Public credit in our security advisory, unless you prefer to remain anonymous.
- No legal action against good-faith security research conducted under this policy.
What We Ask
- Give us a reasonable opportunity to remediate before public disclosure.
- Do not access, modify, or destroy data that is not yours; do not degrade services of Grid Connect or its customers; test only against devices you own or are authorized to test.
- Do not exploit a vulnerability beyond what is necessary to demonstrate it.
Scope
All Grid Connect-branded products with digital elements and their associated firmware, within their published security support period. Issues with the gridconnect.com website are also welcome via the form below. Third-party products we distribute should be reported to the original manufacturer; we will help route the report if you contact us.
Advisories
Fixed vulnerabilities of medium or higher severity are published as Grid Connect Security Advisories on our website, including affected products and versions, severity (Common Vulnerability Scoring System), and remediation instructions. Where applicable we request CVE (Common Vulnerabilities and Exposures) identifiers.