Report a Security Issue (Product Security Disclosure)
Pedarson Ltd (trading as Adept Floor Heating / Adept Technology) is committed to the security of our internet- and network-connectable products, including our underfloor heating thermostats.
This page explains how to report a security issue and what you can expect from us once you have made a report.
This information applies to all Pedarson Ltd relevant connectable products made available to UK consumers.
When To Use This Page
Please use the contact details below if you believe you have found a security issue or vulnerability in one of our products or associated services, for example:
Weaknesses in device firmware or software
Issues with our mobile or web applications used to control the product
Problems with how the product connects to your home network or the internet
Any other behaviour that could reasonably affect the confidentiality, integrity or availability of the product or its data
This page is not for general product support, returns or installation queries. For those, please use our standard customer support contact details.
How To Report A Security Issue:
Please email details of the suspected issue to: [email protected]
When you contact us, it is helpful if you can include:
Product name and model
Where and approximately when you purchased it
A clear description of the issue
Step-by-step instructions to reproduce the problem, if possible
Any screenshots, logs or additional technical details that may help us understand the issue
Please do not include more personal information than is necessary. Avoid sending passwords or highly sensitive personal data.
What You Can Expect From Us:
When you report a security issue using the above contact:
We will acknowledge receipt of your report within 3 working days of receiving it.
We will provide an initial status update within 10 working days after the acknowledgement, once we have carried out a first assessment.
We will then provide status updates at least every 30 days until the reported security issue is resolved or a clear mitigation is communicated.
Our Approach To Security Reports:
We treat all good-faith reports seriously and investigate them.
We aim to remediate confirmed security issues through configuration changes, security updates or other appropriate measures.
Where relevant, we may contact you for further information to help us reproduce or better understand the issue.
We may share high-level information about resolved security issues (for example in release notes), but we will not publish your personal details without your consent.
Privacy:
We will use the information you provide only for the purposes of assessing and addressing the reported security issue and for communicating with you about it.
You do not need to create an account, register the product or provide unnecessary personal information in order to report a security issue.