Skip to content

Security: Kiloiot/.github

Security

SECURITY.md

Security

Reporting a vulnerability

Email info@kiloiot.de. Please do not open a public issue for a security problem.

It helps if you can include the affected product and version, what the issue is, how to reproduce it, and the impact you think it has.

Please do not include credentials, private keys, customer data, or other sensitive production data in your first message. If sensitive evidence is needed, we will arrange a restricted channel for it.

Please give us a reasonable opportunity to fix the issue before disclosing it publicly.

Which company the report concerns

Identify the affected repository or product in the subject. Software-platform reports concern CHIRP USA LLC, which operates the Kilo/Fullchirp platform. Hardware distribution and store reports concern the separate Kilo IoT GmbH, also referred to as Kilo Electronics. Kilo IoT GmbH is not the platform operator.

What this policy does not promise

This file does not set an acknowledgement time, a triage time, a remediation time, a supported-version period, or a disclosure credit. Those commitments are published only once they have been approved, and they are absent here because they are not yet in place.

There aren't any published security advisories