Política de Divulgação de Vulnerabilidades
Philosophy
At AlfredCamera, we are committed to prioritizing the safety and security of our users who entrust us with the protection and monitoring of their homes and loved ones. Recognizing the dynamic nature of cybersecurity, we understand that vulnerabilities may arise despite our best efforts. In line with our dedication to transparency, collaboration, and user safety, we invite the security community to assist us in identifying and addressing potential vulnerabilities. This Vulnerability Disclosure Policy serves as a framework for responsible security researchers to report any discovered vulnerabilities, ensuring a coordinated and swift response. By fostering an open dialogue and partnership with the security community, we aim to continually strengthen the security of our products and uphold the trust placed in us by our users. Your contributions play a vital role in our collective mission to provide reliable security and peace of mind. We appreciate your support in creating a safer digital environment for all users.
Scope
The scope of our vulnerability disclosure policy applies to all hardware products, mobile applications, application programming interfaces, and websites owned, operated, and maintained by AlfredCamera. It is not for reporting general product issues or quality complaints. If you need support with daily product usage, please visit our Help Center at https://support.alfred.camera/.
Reporting a Vulnerability
If a vulnerability is discovered, please provide a detailed summary of the vulnerability, including the following:
- Detailed technical description of the vulnerability and its potential impact;
- Steps required to reproduce the vulnerability, including a description of any tools needed to identify or exploit the vulnerability;
- Product, model, version, and configuration of any software, firmware, or hardware potentially impacted;
- Proof-of-concept (PoC); and
- Suggested mitigation or remediation actions, as appropriate.
Images (e.g., screen captures) and other relevant documents may be attached to reports. We request that any scripts or exploit code be embedded into non-executable file types.
Please email your vulnerability report to security@alfred.camera.
The AlfredCamera Security Team will acknowledge receipt of each vulnerability report, conduct a thorough investigation, and take appropriate action for resolution. We strive to acknowledge receipt of all vulnerability reports within 1-3 business days.
Bug Bounty
We do not have a formal bug bounty program and do not currently reward reporters for their findings.
Questions
Questions regarding this policy may be sent to security@alfred.camera. We also invite security researchers to contact us with suggestions for improving this policy.