Security at mediola (Vulnerability Disclosure Policy)

The security of our hardware and software products and the protection of our customers’ and partners’ data are of the highest priority to mediola – connected living AG. We appreciate the support of our customers and users, security researchers, and other third parties in identifying and responsibly reporting potential security vulnerabilities in our products and services. Responsible vulnerability disclosure helps us continuously improve the security and resilience of our solutions.

Reporting Potential Security Vulnerabilities:
If you believe you have identified a potential security vulnerability, security issue, or other security-related concern affecting our products or services, please report it directly to our Product Security Incident Response Team (PSIRT):

1. Scope

This policy applies to all products, hardware and software solutions, mobile applications, and cloud services developed and distributed by mediola for which mediola acts as the manufacturer within the meaning of the EU Cyber Resilience Act (CRA). This includes, but is not limited to:

  • mediola Matter Bridges
  • mediola Software-Platforms (AIO CREATOR NEO, Viz Designer for HomeKit) & Apps (mediola Connect, AIO REMOTE NEO, IQONTROL NEO)

2. Encrypted Communication

To protect the confidentiality of vulnerability reports and related information during transmission, you may encrypt your report using our public PGP key.

3. Our Response and Remediation Process

Upon receipt of a vulnerability report, we will follow the process outlined below:

PhaseTarget TimeframeAction
Acknowledgement of ReceiptWithin 2 Business Days (Mo-Fr)We acknowledge receipt of your report
Initial AssessmentWithin 5 Business Days (Mo-Fr)We assess the reported vulnerability for validity and severity, for example using the Common Vulnerability Scoring System (CVSS).
Remediation & PatchingPriority basedWe develop, test, and release a security update. Where appropriate, we will provide further information and updates regarding the remediation process.

4. Guidance for Security Researchers (Coordinated Disclosure)

WWhen investigating and reporting potential security vulnerabilities, we kindly ask security researchers to adhere to the following principles:

  • Allow us reasonable time to investigate and remediate the reported vulnerability before disclosing any information publicly (Coordinated Vulnerability Disclosure).
  • Avoid any actions that could negatively impact the availability or performance of our services, including Denial-of-Service (DoS) attacks.
  • Do not access, modify, or delete data belonging to other users.

5. Machine-Readable Security Information (security.txt)

Automated systems and security researchers can find our security contact information and relevant policies in machine-readable format in accordance with RFC 9116 at:

https://www.mediola.com/.well-known/security.txt