Vulnerability Disclosure Policy
European Thermodynamics Ltd - Adaptive® Product Security
How to report
If you believe you have found a security vulnerability in an Adaptive® controller, its firmware, or the AdaptiveThermoLab cloud platform, please email [email protected]. Please include the affected product and version, a description of the issue, and clear steps to reproduce it. Where possible, encrypt sensitive details or request a secure channel before sharing them.
What to expect
- We aim to acknowledge your report within 5 working days.
- We aim to provide a fix or mitigation within 90 days of acknowledgement, and will keep you informed of progress.
- With your agreement, we are happy to credit you in the relevant product changelog once a fix is released.
Scope
In scope:
- Adaptive® thermoelectric controllers and their firmware
- The AdaptiveThermoLab cloud platform and its API
Out of scope:
- Third-party services and infrastructure providers (report those to the provider directly)
- Social engineering, physical attacks, and denial-of-service testing
Safe harbour
We will not pursue or support legal action against researchers who act in good faith, follow this policy, avoid privacy violations and service disruption, and give us a reasonable time to respond before any public disclosure.
Machine-readable contact: /.well-known/security.txt