Vulnerability Disclosure Policy

Last updated: August 12, 2026

1. Purpose

Comu welcomes reports from customers, security researchers, and members of the public who identify potential security vulnerabilities in Comu products or related software. Reporting potential vulnerabilities helps us investigate and address security issues.

2. Scope

This policy applies to potential security vulnerabilities affecting:

  • Comu product devices;
  • Comu product firmware; and
  • Comu applications and software used with supported products.

3. How to Report a Security Vulnerability

You may report a potential security vulnerability through either of the following channels:

4. Information to Include

Where available, please include:

  • The affected product model;
  • The device serial number, if available;
  • The firmware version or Comu App version;
  • A clear description of the issue;
  • Steps to reproduce the issue; and
  • The potential impact and any relevant supporting material.

Please do not include personal information, account credentials, or third-party data that is not necessary for us to investigate the report.

5. What to Expect

We will acknowledge receipt of a security vulnerability report within 5 business days.

We will provide a progress update at least once every 14 calendar days until the issue has been fixed, mitigated, or determined not to be a security vulnerability.

Investigation and remediation times vary depending on the nature, severity, and complexity of the issue. This policy does not set a fixed remediation deadline.

6. General Bugs and Product Feedback

For a general product bug or other product feedback that is not a security vulnerability, please use Me > Help & Feedback in the Comu App or email support@comu.com and identify the message as general product feedback.

7. Contact

Security vulnerability reporting: support@comu.com