Thermia Vulnerability Disclosure Policy

Introduction  

Thermia is committed to ensuring the security of our users by protecting their data and information. This policy gives security researchers clear guidelines for conducting vulnerability discovery activities related to our products and services, and conveys our preferences in how to submit discovered vulnerabilities to us.  

This policy describes which Thermia products and services are covered by this policy, our guidelines for security researchers, our vulnerability reporting process, and our practices for coordinated public disclosure. 

We encourage you to contact us to report potential vulnerabilities in our products and services. 

Authorization  

If you comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the vulnerability quickly, and we will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known. 

Guidelines 

When conducting vulnerability discovery activities related to our products and services you must adhere to the following guidelines: 

  • Only target your own Thermia products and service accounts. 

  • Make sure that targeted products and services are updated to the latest available version. 

  • Notify us as soon as possible after you discover a real or potential security issue. 

  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data. 

  • Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use exploits to compromise or exfiltrate data, establish persistent access, or to pivot to other systems. 

  • Do not otherwise attempt to access anyone else’s data. 

  • Do not publicly disclose a vulnerability until we have agreed on an appropriate disclosure timeline.  

  • Do not threat to withhold vulnerability details, sell the vulnerability to a third party, disclose it publicly or make any other kinds of threats. 

  • Do not submit a high volume of low-quality reports. 

  • Do not violate any law. 

Once you’ve established that a vulnerability exists or encounter any sensitive data (e.g. personal data, financial information, or proprietary information or trade secrets of any party), you must stop your activity, notify us immediately, and not disclose this data to anyone else. 

Unauthorized activities 

The following activities are not authorized: 

  • Targeting Thermia products or service accounts that do not belong to you 

  • Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data 

  • Performing brute-force attacks to gain access to a system 

  • Introducing malware into a system 

  • Making changes to a system 

  • Copying, editing or deleting data in a system 

  • Repeatedly access a system or share access to a system with others 

  • Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing) or any other non-technical vulnerability testing 

  • Fraudulent submissions (e.g. knowingly submitting reports misrepresenting the origin or impact of a vulnerability or deceptive proof-of-concepts) 

Scope 

This policy applies to the following Thermia products and services: 

  • Connected Thermia heat pumps with the Osiria software platform 

  • The MyThermia service 

Products or service not expressly listed above are excluded from the scope of this policy and are not authorized for testing or other vulnerability discovery activities. The same applies to underlying infrastructure or systems from our vendors. Before targeting any vendor’s infrastructure or systems, you should ensure that your planned activities comply with vendor's own vulnerability discovery policy. Vulnerabilities discovered in vendor's infrastructure or systems must be reported directly to the vendor. Thermia assumes no liability whatsoever for your activities involving vendor infrastructure or systems. If you aren’t sure whether a system is in scope or not, contact us at security@thermia.com before starting your activities. 

Though we develop and maintain other internet-accessible products or services, we ask that your activities only be conducted on the systems and services covered by the scope of this policy. If there is a particular product or service not in scope that you think merits testing, please contact us to discuss it first. We will increase the scope of this policy over time.  

Reporting a vulnerability 

We accept vulnerability reports via security@thermia.com. Reports may be submitted anonymously. If you share contact information, we will acknowledge receipt of your report within 3 business days. We do not support PGP-encrypted emails. 

What we would like to see from you 

In order to help us triage and prioritize submissions, we recommend that your reports: 

  • Describe the location the vulnerability was discovered and the potential impact of exploitation.  

  • Offer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful). 

  • Be in English or Swedish, if possible. 

What you can expect from us 

When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible. 

  • Within 3 business days, we will acknowledge that your report has been received.  

  • To the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including on issues or challenges that may delay resolution.  

  • We will maintain an open dialogue to discuss issues. 

Coordinated vulnerability disclosure 

Our vulnerability disclosure process is aligned with cybersecurity legislation. We will process submitted vulnerability reports in accordance with all applicable law, including mandatory notification obligations.  

Personal data 

If your share personal data in your submission (e.g. your e-mail address or name), we will process that data as described in our Privacy Policy. 

Questions 

Questions regarding this policy may be sent to security@thermia.com. We also invite you to contact us with suggestions for improving this policy. 

Contact information 

Thermia AB 
Box 950 
671 29 Arvika 
Sweden 
Reg. No.: 556269-6483 
Web: www.thermia.com 
E-mail: security@thermia.com