linkedin
youtube

North America
For countries not listed, go to the Global site
Oceania
For countries not listed, go to the Global site

Report a Security Vulnerability

AVIRE welcomes reports of security vulnerabilities affecting our products, firmware, cloud services and websites. We operate a Coordinated Vulnerability Disclosure (CVD) process: if you believe you have found a vulnerability, please tell us first and give us the opportunity to investigate and remediate it before the issue is made public.

Reports made in good faith are welcome from anyone — customers, security researchers, partners, installers and end users alike. AVIRE will not pursue legal action against researchers who investigate and report vulnerabilities responsibly and in line with our Coordinated Vulnerability Disclosure Policy (reference AV-CVD-001).

How to contact us

Email our security team at security@avire-global.com, or use the reporting form at the bottom of this page. Both routes reach the same team.

If your report contains sensitive technical detail, exploit code or customer data, please encrypt it. Our PGP public key is published at security.asc.

What to include in your report

The more detail you can give us, the faster we can triage and reproduce the issue. Where possible, please tell us:

  • The affected product, model and firmware or software version.
  • A description of the vulnerability and the impact you believe it could have.
  • Steps to reproduce the issue, or a proof of concept.
  • Any supporting evidence such as logs, configuration details or screenshots.
  • How you would like to be contacted, and whether you wish to be credited publicly.

Please do not access, modify or delete data belonging to other people, and do not run tests that could disrupt a live installation, or a product’s alarm or emergency communication function, or put building occupants at risk.

Good Faith Research

AVIRE supports good-faith security research. Vulnerabilities discovered and reported in good faith, for the purpose of testing, investigating or correcting a security flaw and without malicious intent, are handled under our CVD Policy. We will not pursue legal action against researchers who act in good faith, comply with our CVD Policy (including the testing rules), avoid privacy violations and service disruption, and do not disclose a vulnerability publicly before a coordinated disclosure has taken place.

How we will respond

  • We acknowledge receipt of every report within 1 business day.
  • We assess and triage the report, and keep you informed while we investigate.
  • Where a fix or mitigation is needed, we work on it and coordinate the disclosure timeline with you.
  • If you have consented, we credit you as the reporter in the related security advisory.

Coordinated Vulnerability Disclosure Policy (AV-CVD-001)

AVIRE’s Coordinated Vulnerability Disclosure Policy, document reference AV-CVD-001, sets out the scope of this process, the information we need, how we handle reports, our response commitments and our disclosure principles.

security.txt (RFC 9116)

AVIRE publishes a machine-readable security contact file in accordance with RFC 9116. It lists our security contact address, our PGP key and this reporting page, and is available at security.txt.

Submit a report

Use the form below to send your report straight to AVIRE’s security team. Fields marked with * are required; everything else is optional and simply helps us triage faster.

Please do not include personal data relating to third parties, and do not attach live customer data. If your report is highly sensitive, email it to security@avire-global.com encrypted with our PGP key instead.








    Screenshots, logs or proof of concept · Max 5 files, 10MB each · PDF, TXT, LOG, PNG, JPG, GIF, ZIP