Typhur Vulnerability Disclosure Policy
At Typhur, security is part of the experience we build into every connected product and service. This page is a direct channel for reporting security concerns and working with us toward clear, responsible solutions that help keep Typhur products trustworthy over time.
Report a Vulnerability
Please report suspected security vulnerabilities through the dedicated mailbox. We welcome responsible reports from researchers, customers and partners.
Security reporting mailbox
security@typhur.com
For sensitive information, please do not include passwords, personal data or production secrets unless necessary. We may contact you for clarification.
Information to Include
- Product identification: Product name, model and device serial number (SN)
- Issue description: Clear description of the suspected vulnerability and affected function
- Reproduction evidence: Reproduction steps, proof-of-concept information, logs, screenshots or video
- Reporter details: Name or preferred attribution, organization and security contact details
Typhur accepts anonymous reports. However, we may be unable to verify or investigate the issue further without a follow-up contact.
Severity & Handling Priority
Typhur uses a four-level reference framework to support consistent triage and remediation decisions.
| Reference level | Typical assessment factors | Typical handling |
|---|---|---|
| Critical | Confirmed exploitation, remote control, impact to security-critical controls, or broad compromise of products or cloud services. | Immediate escalation, risk containment and highest remediation priority. Regulatory or customer notification is assessed where applicable. |
| High | A practical attack path that may cause significant impact or affect multiple products, users or services. | Prioritized remediation and coordinated communication with relevant stakeholders. |
| Medium | Limited impact, restricted exploitation conditions, or an effective mitigation already available. | Track and remediate according to product risk, release planning and available mitigation. |
| Low | Light impact, difficult exploitation, defense-in-depth weakness or issue with no material compromise demonstrated. | Record, track and address through appropriate routine security improvements. |
Handling priority: Critical → High → Medium → Low. The final severity and priority may change as facts are verified.
Vulnerability Response & Disclosure
Typhur follows a coordinated process designed to protect users while giving researchers clear communication and appropriate credit.
- Receive report. Reports are received through security@typhur.com and recorded with a tracking reference.
- Validate & assess. We reproduce the issue, identify affected products and assess severity, exploitability and scope.
- Coordinate remediation. Security, engineering, suppliers and service owners develop and verify a fix or risk-reduction measure.
- Notify stakeholders. Where appropriate, we communicate mitigations, security updates and relevant regulatory notifications.
- Coordinate disclosure. After remediation or mitigation, Typhur and the reporter agree on responsible disclosure timing and content.
Vulnerability Disclosure Statement
Typhur supports coordinated vulnerability disclosure and aims to share useful information without increasing risk to users.
Our Approach
- Receive and record valid vulnerability reports.
- Validate the vulnerability, assess its impact and determine its severity.
- Coordinate remediation with the responsible teams.
- Prioritize user protection and avoid premature disclosure that could create additional risk before a fix or mitigation is available.
Disclosure Timing
- Disclosure timing depends on severity, exploitation status, affected products, remediation complexity and user protection.
- Typhur may delay or limit disclosure where publication could increase risk, expose personal data or conflict with legal obligations.
- Public advisories, when issued, may include affected versions, severity, impact, mitigation and update information.
Security Updates & Product Support
Security support is part of Typhur's product lifecycle management.
Typhur will provide security updates or risk-reduction measures based on the affected product, cybersecurity risk, legal obligations and the applicable support period. Security updates will be distributed through appropriate security channels and, where required by applicable law, provided promptly and free of charge.
- Support periods and the availability period for security updates will be communicated through the applicable product support policy, product pages, user documentation or security support lifecycle page.
- Users should promptly install available security updates, use supported Typhur app and device firmware versions, protect account credentials and follow published security guidance.
Disclaimer
This page describes Typhur's intended security reporting and coordinated disclosure practices. It is not a certification, conformity assessment, legal opinion or guarantee that any product is compliant with a particular law or standard. Product-specific support periods, regulatory reporting obligations and response timelines may vary. Typhur may update this page as its processes and applicable requirements evolve.








