Security
Cozyla Coordinated Vulnerability Disclosure Statement
Last Updated: August 28, 2024
Cozyla is consistently dedicated to ensuring the security of our customers who use our products and services.
Security Strategy
Given the comparatively sensitive nature of vulnerability information, we strongly advise you to use our public PGP key for encryption when reporting a potential security vulnerability to Cozyla and to send us the technical details encrypted.
Cozyla PGP Public Key File
-
Please use our public PGP key to encrypt all email submissions to security@cozyla.com.
-
Please provide sufficient contact information (e.g., your company/organization name and your contact person) so that we can get in touch with you.
-
Please provide a technical description of the problem or vulnerability.
-
Please specify which particular product you tested, including the product name and version number.
-
To help us verify the issue, please provide any additional information, including details of the tools used for testing and relevant test configurations.
Software Maintenance Update Strategy
Once a vulnerability has been identified, the firmware will be updated as follows:
-
Identification: Vulnerabilities are reported by users or other parties.
-
Verification: Verification of the reported vulnerability.
-
Remediation: Development of a solution by the Security Technology Manager and the Software Engineer.
-
Validation: Carrying out Quality Assurance (QA) and validation tests for the identified solution.
-
Certification: If Google authentication is required, the relevant components will be submitted to a Google-authorized third-party certification lab for review and approval.
-
Deployment: Delivery of the update via OTA (Over-The-Air).
Response Time
Upon receipt of a vulnerability report, we will acknowledge its receipt and provide feedback within approximately 7 business days. This includes confirming the issue and providing initial feedback. Status updates regarding the development and deployment of the fix will be communicated via email as soon as possible.
Once a vulnerability has been verified, we will disclose detailed information about the issue and the corresponding solution according to the following schedule:
-
Critical Vulnerabilities: Remediation within 30 days;
-
High Vulnerabilities: Remediation within 60 days;
-
Medium Vulnerabilities: Remediation within 90 days;
-
Low Vulnerabilities: Remediation over a longer period.
Notes
Our products receive regular security updates to ensure continuous protection. The predefined support period for security updates ends one year after the product's End-of-Life (EOL) status. This status occurs 3 years after the product's manufacturing date. The product's manufacturing date can be found on the product packaging.
Security Response Plan
Should a security incident occur, it must be treated as an urgent matter with the highest priority. The CEO and CTO must be informed of this incident and participate in managing it. If the incident is a software maintenance issue, it will be handled according to the "Software Maintenance Update Strategy" processes on this page.
A crisis meeting must be convened immediately. The purpose of this meeting is to gather information, clarify the facts of the incident, and estimate the expected timeframe for remediation of the incident.
Legal Notice
In the event that you choose to share information with Cozyla, you agree that the information you submit will be considered non-proprietary and non-confidential, and that Cozyla is entitled to use this information in any manner, in whole or in part and without restriction. Furthermore, you agree that by submitting information, no rights are created for you or obligations for Cozyla.

