Report a Vulnerability
Last updated
Keeping the AssetBook platform and the systems connected to it secure is central to what we do. If you think you've found a vulnerability in one of our products or services, please tell us. We welcome reports from security researchers, customers, partners and anyone else.
How to report
Email security@assetbook.eu. If you don't get a reply, contact info@assetbook.eu and ask to be put in touch with our security team. Reports in English or Swedish are fine.
To help us act quickly, please include:
- which product, app, device, firmware version or URL is affected
- a description of the vulnerability and its possible impact
- steps to reproduce it, or a proof of concept
- how we can reach you, and whether you'd like to be credited
Scope
- the AssetBook IoT Platform and its APIs
- the AssetBook apps for iOS and Android
- AssetBook gateways, firmware and other products we supply
- websites and services on AssetBook domains
If the issue is in a third-party product that integrates with AssetBook, please report it to that manufacturer as well. We're happy to help coordinate.
What you can expect from us
- We'll confirm we've received your report and tell you who is handling it.
- We'll investigate, keep you updated on our progress, and let you know when the issue is fixed.
- We'll inform affected customers and fix or mitigate the issue as quickly as the risk requires.
- With your permission, we'll credit you when we publish information about the issue.
Guidelines for researchers
When investigating a vulnerability, please:
- only access or change the minimum data needed to show the problem, and never data belonging to others
- avoid anything that could disrupt services or connected devices, such as denial-of-service testing
- don't use social engineering, phishing or physical attacks
- give us reasonable time to fix the issue before you disclose it publicly, normally up to 90 days
If you act in good faith and follow these guidelines, we will not take legal action against you for your research.
Machine-readable contact details are published at /.well-known/security.txt.