Vulnerability disclosure
Report security issues affecting Etablone cloud APIs and related Active-ESL Cloudflare surfaces to security@active-esl.com.
Include affected hostnames, a clear description, and steps to reproduce. We aim to acknowledge within 5 business days. Please use coordinated disclosure โ do not publish before we confirm receipt and have a reasonable remediation window.
https://dev.etablone.dynamicdevices.co.uk- /.well-known/security.txt
- Engineering notes: see repository
docs/SECURITY.mdanddocs/CRA-COMPLIANCE.md
Out of scope without prior agreement: physical attacks on customer devices, social engineering of staff, and high-volume DoS testing.