CRA Security Policy

Vulnerability Disclosure Policy

Radiocrafts takes product security seriously and welcomes reports of potential security vulnerabilities in our products and services.

Reporting a Vulnerability

If you believe you have identified a security vulnerability, please send a report to:

cybersecurity@radiocrafts.com

Please include as much information as possible, such as:

  • Product name and version
  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Your contact details if you would like feedback
  • Our Commitment

When we receive a report, we will:

  • Acknowledge receipt as soon as reasonably practical.
  • Assess and investigate the reported issue.
  • Take appropriate actions to mitigate or remediate confirmed vulnerabilities.
  • Keep the reporter informed when appropriate.
  • Responsible Disclosure

We ask that vulnerabilities are not publicly disclosed until Radiocrafts has had a reasonable opportunity to investigate and address the issue.

We also ask that testing is conducted in a manner that does not:

  • Disrupt the availability of systems or services.
  • Compromise data, privacy, or the security of other users.
  • Violate applicable laws or agreements.
  • We appreciate the efforts of security researchers and others who help improve the security of our products.

Radiocrafts supports coordinated vulnerability disclosure and will work with reporters to agree on an appropriate disclosure timeline.