Responsible Disclosure Policy
The IT security of our connected products (Bluetooth, Wi-Fi and mobile-enabled devices from the Carbest, Camp4, Holiday Travel and REIMO TENT brands) is a top priority for us. We value the contributions of security researchers, customers and third parties who bring potential vulnerabilities to our attention, and we are committed to handling such reports in a responsible and transparent manner.
How to report a vulnerability
Please send your report to: [email protected]
This contact channel is intended solely for reporting security vulnerabilities and does not replace our general customer service. Please continue to direct any enquiries regarding orders, complaints or product use to our contact details or FAQs.
What your report should include
- Affected product (model, item number, firmware/software version, if known)
- Description of the vulnerability and its potential impact
- Steps to reproduce the issue, where applicable
- Your contact details for follow-up enquiries (optional, if you wish to remain anonymous)
Confidentiality and coordinated disclosure
We treat every report as confidential. We ask that you do not disclose information about a reported vulnerability publicly before a security update is available or until we have agreed on a disclosure date with you (‘coordinated disclosure’). Reporters acting in good faith and in accordance with this policy need not fear any legal action from us.
Response times
- Acknowledgement of receipt: within 3 working days
- Initial assessment/evaluation: within 14 working days
Next steps
Upon receipt of your report, we will investigate the vulnerability, assess the risk and, if necessary, implement corrective measures (e.g. a security update). As soon as a solution is available, we will inform affected customers via the appropriate channels. A public announcement regarding the resolved vulnerability will only be made after consultation with you.
Scope
This policy applies to connected products under the Reimo brands. For other product safety issues (e.g. mechanical or chemical risks), please visit our Product Recalls page.
How to report a vulnerability
Please send your report to: [email protected]
This contact channel is intended solely for reporting security vulnerabilities and does not replace our general customer service. Please continue to direct any enquiries regarding orders, complaints or product use to our contact details or FAQs.