Skip to main content

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Last updated: 09/08/2026
Effective date: 09/08/2026

Hemro Group ("Hemro", "we", "us") is committed to ensuring the security of our products and services. We value the work of security researchers and the broader community in helping us identify and address potential vulnerabilities. This policy describes how to report a security vulnerability to us and what you can expect from that process.


1. Scope

 

This policy applies to vulnerabilities discovered in:

 

  • Hemro connected products with digital elements, including but not limited to connected grinders, scales, and coffee machines (including their firmware)
  • The Hemro ecosystem app (web and mobile versions)
  • Hemro's cloud backend and APIs supporting connected products
  • Hemro-owned and operated websites and digital infrastructure directly related to the above

 

Out of scope:

 

  • Physical security of Hemro premises or devices (e.g. theft, physical tampering requiring disassembly)
  • Social engineering attacks against Hemro employees or customers
  • Denial-of-service or distributed denial-of-service attacks performed against Hemro infrastructure as part of testing
  • Vulnerabilities in third-party services not under Hemro's direct control (e.g. third-party payment processors, unless the vulnerability is in how Hemro integrates with them)
  • Issues that require physical, non-standard access to a device (e.g. soldering, hardware modification) unless they pose a credible risk to other users
  • Spam, phishing, or social media account issues unrelated to product security

2. How to Report

 

If you believe you have discovered a security vulnerability affecting an in-scope product or system, please report it to us through one of the following channels:

 

 

What to include in your report

 

To help us triage and resolve the issue efficiently, please include:

 

  • A clear description of the vulnerability and its potential impact
  • The product, product version, firmware version, or system affected
  • Step-by-step instructions to reproduce the issue
  • Any proof-of-concept code, screenshots, or supporting evidence
  • Your assessment of severity, if you are able to provide one
  • Your contact information, if you wish to be kept informed of remediation progress

3. What You Can Expect From Us

 

We are committed to responding to vulnerability reports in a timely and transparent manner:

 

StageTimeline
Acknowledgement of your reportWithin 72 hours of receipt
Initial assessment and severity classificationWithin 10 business days
Regular status updatesAt least every 2 weeks until resolution, for confirmed vulnerabilities
Remediation timeline communicationProvided once severity is confirmed, commensurate with the risk

We will keep you informed of our progress throughout the process, to the extent that doing so does not compromise the security of the fix or the privacy of other parties.


4. Our Commitment to Responsible Disclosure (Safe Harbour)

 

We consider security research conducted in accordance with this policy to be:

 

  • Authorised in accordance with applicable anti-hacking laws, and we will not pursue or support legal action against researchers for accidental, good-faith violations of this policy
  • Authorised in relation to relevant anti-circumvention laws, and we will not bring a claim for circumvention of technology controls against you for security research activities conducted in accordance with this policy
  • Exempt from restrictions in our Terms of Service that would interfere with conducting security research, to the extent that such restrictions would otherwise apply

 

This safe harbour applies only to testing conducted in accordance with this policy. If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.


5. Our Expectations of Researchers

 

To protect our users and enable us to address vulnerabilities responsibly, we ask that you:

 

  • Give us reasonable time to investigate and remediate an issue before disclosing it publicly (we ask for a minimum of 90 days from initial report, or until a fix is released, whichever is shorter — to be confirmed)
  • Make a good faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services during your research
  • Only interact with accounts, data, or devices you own or for which you have explicit permission to test
  • Do not exploit a vulnerability beyond what is necessary to confirm its existence (e.g. do not exfiltrate data beyond a proof of concept, do not pivot to other systems)
  • Do not publicly disclose vulnerability details before we have had the opportunity to address the issue, in accordance with the coordinated disclosure timeline above

6. Regulatory Context

 

Hemro is committed to compliance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847). This policy forms part of our coordinated vulnerability disclosure obligations under Article 13 and Annex I, Part II of that Regulation.


7. Changes to This Policy

 

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision.