Vulnerability Disclosure Policy
Last updated: July 24, 2026 · Version 1.0
Stovyn protects people from kitchen fires, so the security of our devices, firmware, apps, and services matters as much as their safety. We welcome reports from security researchers and will work with you to understand and resolve any issue quickly. This policy explains what is in scope, how to report, and the protections we extend to good-faith research.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider it authorized, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity that complied with this policy, we will make that authorization known.
How to report
Email security@stovyn.com. Please include:
- ·A clear description of the vulnerability and its potential impact.
- ·Step-by-step instructions to reproduce it, including any proof-of-concept.
- ·The affected product, URL, app version, or firmware version.
- ·How you would like to be credited, if you would like public acknowledgment.
Our machine-readable contact details are published at /.well-known/security.txt (RFC 9116).
Scope
In scope
- stovyn.com and its subdomains
- The Stovyn mobile apps (iOS and Android)
- Stovyn device firmware and its update mechanism
- Our backend APIs and cloud services
Out of scope
- Denial-of-service or volumetric testing
- Social engineering of our staff or customers
- Physical attacks against offices or hardware you do not own
- Spam, or findings from automated scanners without demonstrated impact
- Third-party services we do not operate
Rules of engagement
- ·Only test against your own account, your own device, or accounts you have explicit permission to use.
- ·Do not access, modify, or delete data that is not yours, and stop as soon as you can demonstrate a vulnerability.
- ·Never interfere with a device's safety functions on a unit in real use.
- ·Give us a reasonable time to fix an issue before disclosing it publicly, and coordinate the timing with us.
What you can expect from us
- ·We aim to acknowledge your report within 3 business days.
- ·We will keep you updated as we investigate and remediate.
- ·With your permission, we will credit you once the issue is resolved.
We do not currently run a paid bug-bounty program, so no monetary reward is offered — but we value every good-faith report and will acknowledge your contribution. For our update and support windows, see Security & Updates.
Stovyn is a product of Augeas Technologies Partnership Company. Security contact: security@stovyn.com.
We use cookies to improve your experience
We use essential cookies to make our site work. With your consent, we may also use non-essential cookies to improve user experience. Learn more
