Last updated: 24 July 2026
1. Our commitment
We take the security of our products and services seriously. We welcome reports from security researchers and members of the public who identify a potential vulnerability, and we aim to work with reporters in good faith to understand and address genuine issues.
2. How to report
Report a suspected vulnerability to security@simpled.tech with your message marked "Security Vulnerability". Please include, where you can:
- a description of the vulnerability and the product, app, version or URL affected;
- the steps needed to reproduce it;
- proof-of-concept detail (screenshots, logs, request/response) sufficient to demonstrate the issue;
- the potential impact as you see it;
- how we can contact you.
Please report privately and do not disclose the issue publicly until we have had a reasonable opportunity to investigate and remediate.
3. Scope
In scope, in principle: the Simpled website and online store, the Simpled app, Simpled smart-lock firmware, and our directly operated online services.
Out of scope (please do not test these, and reports on them may not be actioned):
- third-party services, platforms or integrations we do not control (for example app stores, voice-assistant or smart-home platforms, payment providers, hosting providers);
- physical attacks against premises, devices or staff;
- social engineering, phishing, or attacks against our people or customers;
- denial-of-service, resource-exhaustion or volumetric testing;
- reports produced solely by automated scanners without a demonstrated, exploitable impact;
- issues requiring an unlikely level of user interaction, or purely theoretical issues with no realistic impact.
4. Rules for good-faith testing
When investigating, you must:
- act in good faith and only to the extent necessary to identify and demonstrate a vulnerability;
- not access, modify, delete or exfiltrate data that is not your own; use only test accounts and your own devices;
- not degrade, disrupt or damage our services or other users' access;
- not violate any person's privacy rights;
- stop and contact us if you encounter personal data;
- comply with all applicable laws, including the Computer Fraud and Abuse Act and applicable state computer-crime laws.
Actions outside these rules — including unauthorized access, data exfiltration, service disruption, extortion, or public disclosure before remediation — are not authorized and fall outside any protection described below.
5. Coordinated disclosure
We prefer coordinated disclosure. We ask that you give us a reasonable period to investigate and remediate before any public disclosure, and that you coordinate the timing and content of any disclosure with us. We may credit reporters who wish to be named, once an issue is resolved.
6. Our process and indicative timescales (targets, not a guarantee)
These are targets, not contractual commitments; actual timing depends on complexity, third-party dependencies and available information.
- Acknowledgment: we aim to acknowledge receipt of a well-formed report within 5 business days.
- Triage: we assess validity, severity and impact, and aim to give an initial assessment within a reasonable period after acknowledgment.
- Status updates: we aim to keep you reasonably informed of progress on a valid report at reasonable intervals — typically at least every 30 days, or sooner for higher-severity issues — until the reported issue is resolved.
- Remediation: we aim to remediate valid issues on a timescale proportionate to their severity.
- Resolution: we aim to confirm when a reported issue has been resolved.
7. Safe harbor (limited)
To the extent it is within our control and lawful, we will not pursue or support legal action against a reporter who, in good faith, complies with this policy — in particular sections 3 and 4 — and reports promptly and privately. We consider such activity authorized under the Computer Fraud and Abuse Act and applicable anti-hacking laws to the extent this policy allows. This does not authorize conduct that breaks the law or affects third parties, and it cannot bind third parties, other users, or government authorities. If in doubt about whether an action is authorized, contact us first.
8. No bounty
Unless we state otherwise for a specific program, we do not operate a paid bug-bounty and make no offer of payment for reports.
9. Contact
security@simpled.tech (mark your message "Security Vulnerability"). If you would rather use our general contact address, support@simpled.tech reaches us too — mark it the same way. Neither is a separately staffed mailbox, so please allow for the timescales in §6. See also our Acceptable Use Policy and Support Lifecycle & Security Updates page.