Security
Security & Responsible Disclosure
We take the security of our products and systems seriously and welcome responsible reports from security researchers.
Scope
This policy covers the ohoya Heliostat One (device and firmware), the ohoya Heliostat App (iOS), and the services we operate at ohoya.de, app.ohoya.de and shop.ohoya.de, including our cloud relay.
Coordinated disclosure
We ask for responsible, coordinated disclosure: please give us a reasonable opportunity to investigate and address an issue before any public disclosure — as a guideline, 90 days. For actively exploited vulnerabilities, we'll agree on a shorter timeline together.
How to report
Please send reports to security@ohoya.de. Helpful details include: a description of the vulnerability and its impact, steps to reproduce, the affected version (app build number or firmware version), and your contact details for follow-up.
Response time
We aim to acknowledge your report within 72 hours and provide an initial assessment (severity, affected scope) within 10 business days. We'll keep you informed as we investigate and address the issue.
Safe harbor
If you follow this policy, we will not pursue legal action against you. In return, we ask that you: avoid disrupting our operations (no denial-of-service testing, no spam, no social engineering of our staff or customers); not access, alter, or exfiltrate third-party data — if you encounter it, please stop and report it to us; and not physically tamper with devices you don't own. Security research on your own device, including reading out your own firmware, is explicitly permitted.
Out of scope
Reports based solely on automated scanner output without demonstrated exploitability; missing "best practice" headers with no concrete impact; vulnerabilities in third-party services we don't operate.
Regulatory reporting
As a manufacturer, we're subject to the EU Cyber Resilience Act's reporting obligations: for actively exploited vulnerabilities and serious incidents, we report an early warning within 24 hours, a report within 72 hours, and a final report within 14 days to the relevant authority (ENISA/CSIRT). Confirmed vulnerabilities are fixed via signed firmware updates (OTA) or app updates; security-relevant updates are flagged in the release notes.
Bug bounty
We're a pre-Series-stage startup and do not currently offer a paid bug bounty program.
Recognition
With your agreement, we're happy to credit you by name in an acknowledgements section once an issue is resolved.