Vulnerability Disclosure Policy
Last updated: 09/08/2026
Effective date: 09/08/2026
Hemro Group ("Hemro", "we", "us") is committed to ensuring the security of our products and services. We value the work of security researchers and the broader community in helping us identify and address potential vulnerabilities. This policy describes how to report a security vulnerability to us and what you can expect from that process.
1. Scope
This policy applies to vulnerabilities discovered in:
- Hemro connected products with digital elements, including but not limited to connected grinders, scales, and coffee machines (including their firmware)
- The Hemro ecosystem app (web and mobile versions)
- Hemro's cloud backend and APIs supporting connected products
- Hemro-owned and operated websites and digital infrastructure directly related to the above
Out of scope:
- Physical security of Hemro premises or devices (e.g. theft, physical tampering requiring disassembly)
- Social engineering attacks against Hemro employees or customers
- Denial-of-service or distributed denial-of-service attacks performed against Hemro infrastructure as part of testing
- Vulnerabilities in third-party services not under Hemro's direct control (e.g. third-party payment processors, unless the vulnerability is in how Hemro integrates with them)
- Issues that require physical, non-standard access to a device (e.g. soldering, hardware modification) unless they pose a credible risk to other users
- Spam, phishing, or social media account issues unrelated to product security
2. How to Report
If you believe you have discovered a security vulnerability affecting an in-scope product or system, please report it to us through one of the following channels:
What to include in your report
To help us triage and resolve the issue efficiently, please include:
- A clear description of the vulnerability and its potential impact
- The product, product version, firmware version, or system affected
- Step-by-step instructions to reproduce the issue
- Any proof-of-concept code, screenshots, or supporting evidence
- Your assessment of severity, if you are able to provide one
- Your contact information, if you wish to be kept informed of remediation progress
3. What You Can Expect From Us
We are committed to responding to vulnerability reports in a timely and transparent manner:
| Stage | Timeline |
|---|---|
| Acknowledgement of your report | Within 72 hours of receipt |
| Initial assessment and severity classification | Within 10 business days |
| Regular status updates | At least every 2 weeks until resolution, for confirmed vulnerabilities |
| Remediation timeline communication | Provided once severity is confirmed, commensurate with the risk |
We will keep you informed of our progress throughout the process, to the extent that doing so does not compromise the security of the fix or the privacy of other parties.
4. Our Commitment to Responsible Disclosure (Safe Harbour)
We consider security research conducted in accordance with this policy to be:
- Authorised in accordance with applicable anti-hacking laws, and we will not pursue or support legal action against researchers for accidental, good-faith violations of this policy
- Authorised in relation to relevant anti-circumvention laws, and we will not bring a claim for circumvention of technology controls against you for security research activities conducted in accordance with this policy
- Exempt from restrictions in our Terms of Service that would interfere with conducting security research, to the extent that such restrictions would otherwise apply
This safe harbour applies only to testing conducted in accordance with this policy. If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
5. Our Expectations of Researchers
To protect our users and enable us to address vulnerabilities responsibly, we ask that you:
- Give us reasonable time to investigate and remediate an issue before disclosing it publicly (we ask for a minimum of 90 days from initial report, or until a fix is released, whichever is shorter — to be confirmed)
- Make a good faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services during your research
- Only interact with accounts, data, or devices you own or for which you have explicit permission to test
- Do not exploit a vulnerability beyond what is necessary to confirm its existence (e.g. do not exfiltrate data beyond a proof of concept, do not pivot to other systems)
- Do not publicly disclose vulnerability details before we have had the opportunity to address the issue, in accordance with the coordinated disclosure timeline above
6. Regulatory Context
Hemro is committed to compliance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847). This policy forms part of our coordinated vulnerability disclosure obligations under Article 13 and Annex I, Part II of that Regulation.
7. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision.