CVD Policy
Coordinated Vulnerability Disclosure Policy
Scope and Principles
This CVD policy is written primarily for security researchers.
All Utonomy products with digital elements are within the scope of this policy; hardware, firmware, embedded software, cloud services, web and mobile applications, the associated documentation, and supporting update mechanisms.
The goals of this policy are to deliver; effective user protections, timely remediation, transparent and responsible disclosure, and multi‑party coordination when third‑party components are involved.
The guiding principles applied include external disclosure in line with IEC 29147:2018, internal handling in line with IEC 30111:2019, and CRA manufacturer obligations. Good practices from BSI TR‑03183‑3 are considered along with ENISA CVD guidance.
How to Report a Vulnerability
We welcome reports from customers, researchers, partners, and the wider security community.
Initial contact with Utonomy (first contact)
Please make initial contact with our team using the email address below.
DO NOT send CONFIDENTIAL or SENSITIVE information, or TECHNICAL SPECIFICS of the vulnerability via email.
Utonomy will respond to your email, and provide a secure communication channel for you to transfer the relevant information.
Email: security@utonomy.co.uk (preferred for initial contact)
What to include in any vulnerability report
The information below must only be sent using a Utonomy approved secure communication channel. DO NOT use email.
-
Product name, exact version/build, and environment (device model, firmware/app version, cloud tenant/URL).
-
Vulnerability type and impact (e.g., CWE if known), prerequisites (auth/user interaction), and security property affected (confidentiality, integrity, availability, safety).
-
Reproduction steps and proof‑of‑concept (PoC); logs, packet captures, screenshots if available.
-
Your contact details and disclosure preference (e.g., timeline). Indicate if you wish to remain anonymous or be credited.
It is really important to avoid any testing that may harm users or services, including: active exploitation of customer data, social engineering against our staff or customers, physical attacks on facilities, or DoS/traffic floods against production systems.
If you believe that a test may cause disruption, please coordinate with Utonomy first.
What You Can Expect
We follow IEC 29147:2018 coordinated disclosure practices and keep reporters informed throughout.
-
Acknowledgement: We reply swiftly with a tracking ID and next steps.
-
Assessment and coordination: We verify scope and severity, may request additional details, and coordinate embargo timing to reduce risk to users.
-
Remediation planning: We develop a fix or mitigation, validate it, and prepare advisory content and update guidance.
-
Advisory and credit: On release of fixes, we publish a security advisory to our customers. In line with CAF recommendations for technologies associated with critical national infrastructure (CNI) Utonomy does not generally disclose vulnerabilities publicly, or publicly credit reporters.
Utonomy aim to coordinate disclosure windows that balance urgency and safety. We ask reporters to work with us on suitable timelines.
Coordinated Disclosure Timelines (Targets)
Target service levels guide our response; actual timelines may vary based on the nature of the exploitation, the complexity, and any safety considerations.
Critical (CVSS ≥ 9.0)
-
Acknowledge Reporter: Within 24 hours
-
Complete Triage: Within 3 days
-
Fix Available: Within 14 days
High (CVSS 7.0 – 8.9)
-
Acknowledge Reporter: Within 2 days
-
Complete Triage: Within 7 days
-
Fix Available: Within 30 days
Medium (CVSS 4.0 – 6.9)
-
Acknowledge Reporter: Within 3 days
-
Complete Triage: Within 14 days
-
Fix Available: Within 90 days
We will discuss and agree any deviations to the timelines above with the reporter of the vulnerability, especially in safety‑critical contexts, or where a vulnerability is actively being exploited.
Safe Harbour and Good‑Faith Research
If you comply with this policy while investigating and reporting a vulnerability to us, we will not pursue or support legal action against you for research conducted in good faith.
This safe harbour does not apply to actions that are unlawful or harmful, such as extortion, threats, or exploitation of data, and presumes that you promptly report the vulnerability with sufficient detail, and that you give us a reasonable time to remediate before public disclosure.
Our Coordination and Disclosure Outputs
For confirmed issues, we prepare and publish a security advisory to our customers, with any disclosure typically containing:-
-
Security advisory contents: Summary; affected products/versions; severity (CVSS vector/score); impact; exploitation status; mitigations/workarounds; fixed versions and upgrade steps; references (e.g., CWE/CVE); reporter credit (if consented).
-
Distribution: Customer portal, mailing lists, support channels, and coordination with upstream/downstream suppliers as needed.
-
Machine‑readable advisories: Utonomy may consider such formats in future.
Controlled public disclosure
In line with the NCSC cyber assessment framework (CAF) and EU NIS2 directive for technologies associated with critical national infrastructure (CNI) Utonomy does not disclose vulnerabilities publicly by default. Where controlled public disclosure is deemed necessary following risk assessment, and with customer impact at the forefront of our considerations, such disclosure will be via our website.
Multi‑Party and Third‑Party Coordination
When a vulnerability involves an upstream dependency, OEM, or component vendor, we will:-
-
Notify and coordinate with the affected party and relevant coordinators (e.g., national CSIRTs) as appropriate to achieve timely fixes across the supply chain.
-
Avoid revealing specific exploit details publicly before mitigations or updates are reasonably available to customers.
If a coordinator/national CSIRT is already engaged by the reporter of the vulnerability, we will work constructively within that process.
Privacy and Confidentiality
We treat vulnerability reports and reporter identities as confidential and use information only for remediation and coordination. We minimise data collection, secure records with access control, and retain such information only as long as needed for remediation, audit, and legal purposes.
Rules of Engagement for Research
Utonomy encourage responsible discovery and reporting of vulnerabilities however, to ensure a safe and productive collaboration, we ask reporters to respect the conduct that we expect.
If you adhere to this policy when reporting a potential security vulnerability to Utonomy we will not pursue legal action or enforcement actions against you in response to your report.
Conduct
We ask that you:-
-
Allow reasonable time for mitigation: Give us a reasonable amount of time to investigate and mitigate any reported issue before disclosing it publicly or sharing it with others. Depending on the complexity of the issue, this might take 90 days or more.
-
Respect customer data: Do not interact with, modify, or access data from a Utonomy customer or potential customer without their explicit consent.
-
Avoid privacy violations and disruptions: Make a good faith effort to avoid violating privacy, destroying data, or causing interruptions or degradation of our services.
-
Do not exploit vulnerabilities: Refrain from exploiting any security issue you discover. This includes demonstrating additional risks or probing for further issues, such as attempting to compromise sensitive company data.
-
Adhere to laws and regulations: Ensure that you do not violate any applicable laws or regulations while conducting your research.
By following these guidelines, you help maintain a secure and cooperative environment for vulnerability disclosure
Prohibited security research activities
Utonomy does not permit the following types of security research:
Negative impact actions
Performing actions that may harm Utonomy or our partner services, systems, or users, such as:-
-
Spam, brute force attacks, or credential stuffing
-
Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
-
Actions causing device malfunctions or service interruptions
Unauthorized data access
Accessing, attempting to access, or tampering with data, configurations, or accounts that do not belong to you, including:-
-
Device telemetry data
-
Device certificates or provisioning credentials
Data destruction or corruption
Destroying, modifying, corrupting, or attempting to harm data, firmware, or configurations belonging to Utonomy, our partners, or users.
Attacks on personnel, property, or devices
Conducting any kind of attack, including:-
-
Electronic attacks on hardware devices, gateways, or IoT endpoints
-
Physical attacks on Utonomy personnel, offices, or data centers
Social engineering
Attempting to manipulate or deceive Utonomy personnel, contractors, or support teams through phishing, impersonation, or other social engineering tactics.
Use of high-throughput automated tools
Deploying automated tools or scripts that generate excessive traffic or disrupt device communications, APIs, or platform services.
Firmware tampering
Modifying or reverse-engineering firmware or software beyond authorized scopes to identify vulnerabilities.
Unauthorized device onboarding
Attempting to onboard unauthorized devices or abusing device provisioning mechanisms.
Interference with multi-tenancy
Testing for vulnerabilities that impact or compromise other tenants’ data, devices, or services.
Physical device access or manipulation:
Gaining unauthorized physical access to Utonomy -connected IoT devices, hardware, or gateways.
Legal and contractual violations:
Breaching any laws, agreements, or terms of service while conducting security research.
Credits and Recognition
With permission, and inline with CAF and industry best practice for CNI technologies, we recognise contributors who help make our products safer. Anonymous credit is supported if preferred.
Contact and Further Information
To report a vulnerability or ask questions about this policy, please contact our Product Security team:
Email: security@utonomy.co.uk
Policy Versioning and Updates
We review this policy periodically and may update it to better reflect standards, regulatory requirements, and community best practice.
The latest version of this CVD policy is always available on our website.
FAQs
- Utonomy does not offer monetary rewards. We value responsible reporting and will publicly acknowledge researchers (with consent, and where CAF and industry norms permit) however there is no formal bug bounty programme.
- If a third‑party component or coordinator is involved, we may share relevant technical details under confidentiality to facilitate timely remediation across our supply chain.