Security Vulnerability Reporting
Vencha takes the security of our smart and connected products seriously.
If you believe you have identified a security vulnerability affecting a Vencha smart or connected product, please report it to us at:
What to include in your report
To help us investigate the issue, please provide as much of the following information as possible:
- The Vencha product name and model number
- A description of the suspected security vulnerability
- Details of how the issue was identified
- Steps required to reproduce the issue, where applicable
- Any screenshots, logs or other supporting information
- Your contact details if you would like us to contact you regarding the report
Please do not include passwords, account credentials or other sensitive personal information unless specifically requested by us.
What happens after you report an issue
We will acknowledge receipt of a security vulnerability report within 3 business days.
We will review the information provided and investigate the reported issue. Where the issue involves technology, software or services provided by a third-party technology provider, we may work with that provider to investigate and resolve the matter.
Where appropriate, we will provide the person who reported the issue with updates on the progress of our investigation and remediation until the issue has been resolved or otherwise closed.
The time required to resolve an issue will depend on its nature, severity and complexity.
Security Support Period
Vencha provides security support for applicable smart and connected products for a defined support period.
For the RWS smart ceiling fan ranges, security support will be provided until at least 31 August 2029.
This support period may be extended where necessary, including to ensure that security support continues for a minimum of 2 years after the product is last sold by Temple & Webster. The published support period will not be shortened.
Responsible disclosure
We ask security researchers and customers to act responsibly when investigating or reporting suspected vulnerabilities.
Please:
- Make reasonable efforts to avoid accessing, modifying or deleting other people's data
- Avoid disrupting Vencha products, systems or services
- Do not use a vulnerability for fraudulent or malicious purposes
- Give Vencha a reasonable opportunity to investigate and address the issue before publicly disclosing technical details
Scope
This reporting process applies to security vulnerabilities affecting Vencha smart and connected consumer products.
For general product support, warranty claims, installation assistance or other non-security enquiries, please use our normal customer support channels.
Contact
Security vulnerability reports:
security@vencha.net.au
Vencha Pty Ltd
Australia