Report a security issue
Thank you for helping us keep Kettle Companion products and services secure.
How to report an issue
If you believe you have found a security vulnerability affecting a Kettle Companion product or a service operated by Dynamic Devices Ltd, email security@kettlecompanion.com.
For an issue that may present an immediate or widespread risk, include URGENT in the subject line.
When you will hear from us
- We will acknowledge your report within two working days.
- We will provide an initial status update within ten working days.
- We will provide further updates at least every ten working days until the reported issue is resolved.
- Reports indicating an urgent risk will be escalated as soon as they are received.
What to include
Please provide as much of the following as you can:
- the affected product, website or service;
- the model, firmware or software version, if known;
- a clear description of the issue and its possible impact;
- steps we can use to reproduce it safely;
- sanitised screenshots, logs or other supporting evidence; and
- how you would like us to contact you.
Please do not send passwords, API keys, unnecessary personal information or full exploit code in your first email. Tell us if you need a more secure way to transfer sensitive technical material.
Scope
This policy covers security issues in systems operated by Dynamic Devices Ltd for Kettle Companion, including:
- Kettle Companion devices and their firmware;
- the Kettle Companion smart plug and its firmware;
- the cloud service needed for the product's intended operation; and
- kettlecompanion.com.
Services run entirely by another organisation are outside this policy. Please report those issues to the organisation that operates the service.
Responsible security research
When investigating or reporting an issue, please:
- act in good faith and avoid harm to people, products, services and data;
- use only accounts and devices you own or have explicit permission to test;
- stop testing and report the issue if you encounter personal or confidential information;
- do not copy, retain, alter or disclose data beyond the minimum needed to demonstrate the issue;
- do not disrupt services, degrade product operation, use social engineering or attempt physical harm; and
- give us a reasonable opportunity to investigate and reduce customer risk before public disclosure.
Dynamic Devices Ltd does not intend to pursue legal action against good-faith research carried out and reported in accordance with this policy. This policy does not authorise access to another person's device, account or data, and it does not waive any third party's rights.
We do not currently operate a paid bug-bounty programme.
How we handle reports
We will assess the report, investigate affected products or services and work towards an appropriate correction or mitigation. We will limit access to report information to people who need it for investigation and response. We will work with reporters on responsible disclosure timing where publication may help customers without creating avoidable risk.
Security support period
Each complete Kettle Companion pack is supported with security updates for five years from the date that pack is shipped to its customer. The support covers the firmware and any cloud service required for the product's intended operation.
Product support and emergencies
This address is for security reports. For ordinary product or account support, please use the contact details on our main website.
Kettle Companion is not an emergency service. If you believe somebody is in immediate danger, contact the appropriate emergency service.