Vulnerability Disclosure Process
We encourage security researchers and customers to report potential vulnerabilities responsibly.
1. Prepare your report
- Include detailed description of the issue, affected product/version, and reproduction steps.
- Attach proof-of-concept if available.
2. Encrypt your report
- Use our “PGP public key” to encrypt sensitive information before sending.
3. Submit your report
- Send the encrypted report to “security@yourcompany.com”.
4. Acknowledgement & Response
- We will acknowledge receipt within “48 hours”.
- Our security team will investigate and provide updates.
- Coordinated disclosure will be followed in line with industry best practices.
Notes
- Please do not publicly disclose vulnerabilities before our team has confirmed and issued a fix.
- For non-security inquiries, contact our general support team at support@yourcompany.com.
Critical vulnerability reports should be sent to:
security@senselock.com
Recommended email subject format: - [CRITICAL][Clave2][sdk-2.3.1.1][fw-3.03]
Information Customers Should Provide
Customer name and security contact;
Product and release version;
SDK version;
Firmware version;
Affected operating system and deployment environment;
Affected SDK, driver, tool, or firmware artifact;
Technical vulnerability description;
Reproduction steps or proof-of-concept details;
Observed or potential impact;
Whether exploitation is suspected or confirmed;
Urgency and customer reporting deadline;
Requested coordination timeline.

