Coordinated Vulnerability Disclosure (CVD) Policy

Mill International AS

Last Updated: 30.08.2026

Expires: 2027-08-28T00:00:00.000Z

At Mill International AS, security and reliability are fundamental to our connected ecosystem—spanning our IoT hardware (heaters, air purifiers, air sensors), mobile applications, and cloud services. We recognize the key role security researchers, open-source developers, and our user community play in keeping our products safe.

This Coordinated Vulnerability Disclosure (CVD) policy outlines how we receive, triage, and remediate vulnerability reports across our hardware, mobile apps, and cloud infrastructure. This policy is established in alignment with the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

1. Scope

In-Scope

This policy applies to all hardware products, embedded firmware, mobile applications, public APIs, and AWS-hosted cloud infrastructure managed by Mill International AS, including:

  • IoT Hardware & Firmware: Connected heaters, air purifiers, air sensors, and integrated microcontrollers/wireless modules (Wi-Fi, BLE, Matter).
  • Mobile Applications: Official Mill International AS applications available on iOS (App Store) and Android (Google Play Store), including local device provisioning and local network control protocols.
  • AWS Cloud Platform & Services: Remote backend processing solutions, AWS IoT Core endpoints, API Gateways, microservices, database layers, and user authentication portals hosted under com.
  • Public APIs & Official Developer Tools: Publicly accessible REST, Webhooks, or MQTT APIs.
  • Third-Party & Open-Source Dependencies: Third-party components, open-source libraries, RTOS, and protocol stacks as integrated into our hardware, apps, or cloud services.

Out-of-Scope

  • Community-Developed Integrations: Third-party code, unofficial plugins, or custom scripts created independently by the community (e.g., custom Home Assistant components) unless the vulnerability stems from a flaw in our underlying Public API or cloud authentication.
  • Other Users’ Accounts & Data: Any testing that involves accessing, modifying, or compromising account data belonging to other users. Researchers must test using their own registered accounts and owned devices.
  • Service Infrastructure: AWS infrastructure owned directly by Amazon Web Services (report directly to AWS).
  • Denial of Service: DoS/DDoS attacks against AWS APIs, MQTT brokers, mobile apps, or hardware devices.
  • Physical & Social Attacks: Physical intrusion against facilities/data centers or phishing/social engineering targeted at staff or users.
  • Low-Impact/Unvalidated Findings: Scanner output without manual validation/PoC, missing non-critical HTTP headers, or software version disclosure without a demonstrated path to exploitation.

2. Guidelines for Testing Public APIs & Community Integrations

We support our active developer community and encourage security research into our public API. However, to protect our infrastructure and third-party integrations, you must follow these rules during research:

  1. Use Dedicated Test Accounts: Always conduct research using your own accounts, API tokens, and physical devices. Never attempt to access or modify data across account boundaries.
  2. API Rate Limiting & Performance: Do not execute automated scanning tools at rates that degrade cloud service performance or affect third-party community integrations relying on our platform.
  3. Flaws Impacting Community Integrations: If you discover a vulnerability in our Public API that impacts open-source platforms (e.g., Home Assistant, Homebridge), please notify us via this policy so we can patch the underlying API endpoint without breaking community ecosystems.

3. How to Submit a Report

If you discover a vulnerability in our hardware, mobile apps, cloud platform, or public API:

  • Primary Contact:security@millnorway.com
  • Encrypted Communication: To transmit sensitive PoCs, API tokens, or exploit details, request our PGP public key in your initial message or retrieve it from [](
  • Preferred-Languages: EN, NO, PL

Please Include in Your Submission:

  1. Target Component: Device model/firmware version, Mobile App version (iOS/Android), API endpoint path, or AWS cloud service affected.
  2. Vulnerability Summary: Clear explanation of the flaw and potential security/safety impact (e.g., broken object-level authorization (BOLA) in the public API, thermal control bypass, privilege escalation).
  3. Reproduction Steps: Step-by-step instructions, sample HTTP requests, curl commands, or a minimal Proof-of-Concept (PoC) script.
  4. Researcher Attribution: Your preferred name/handle (for public credit) and contact details, or an explicit statement requesting anonymity.

Note: Limit data collection to the absolute minimum necessary to demonstrate the issue. Do not exfiltrate customer telemetry, personal data, or cloud credentials.

4. Commitments & Response Timelines

We prioritize security issues based on severity, especially those affecting physical safety (heaters), user privacy, or platform-wide cloud integrity.

Phase

Timeline / Target

Action

Acknowledgment

Within 48 hours

Receipt confirmation and assignment of a tracking ticket.

Initial Triage

Within 5 business days

Assessment of vulnerability validity, initial CVSS scoring, and scope evaluation (Cloud vs. App vs. Firmware).

Status Updates

Every 14 business days

Updates on remediation progress, patch development, and deployment schedule.

Remediation Target

90 calendar days

Deployment of cloud API hotfixes, mobile app store updates, or Over-The-Air (OTA) firmware updates.

Security Support Period (EU CRA Compliance)

Under Regulation (EU) 2024/2847 (Cyber Resilience Act), Mill International AS provides security updates free of charge for all hardware, firmware, cloud backends, and mobile apps throughout the product’s Guaranteed Security Support Period (10 years) from purchase date). Details are available at [https://intercom-help.eu/mill-norway/en/articles/821518-guaranteed-security-support-period](https://intercom-help.eu/mill-norway/en/articles/821518-guaranteed-security-support-period).

Mandatory Regulatory Reporting (EU CRA Article 11)

For products placed on the EU market, if a vulnerability is actively exploited in the wild or presents a severe systemic risk across our cloud or device fleet, Mill International AS will report the incident to the relevant national CSIRT and ENISA within statutory CRA deadlines. This process is managed internally and does not alter how you report issues to us.

5. Coordinated Disclosure Principles

  1. Standard Embargo Window: We ask researchers to maintain confidentiality for 90 calendar days from initial acknowledgment. This provides time to deploy server-side cloud fixes, push mobile app store updates, and safely roll out OTA firmware updates across active fleets.
  2. Firmware & Physical Safety Logistics: Fixing hardware firmware (particularly heating elements) requires safety testing to prevent physical hazards or device bricking. If an OTA update requires extended testing, we will communicate early to establish a mutually agreed disclosure timeline.
  3. Coordinated Advisories: We support joint releases. Draft release notes and CVE descriptions will be shared with you for review prior to public release.

6. Safe Harbor

Mill International AS considers security research conducted in accordance with this policy to be authorized, lawful, and conducted in good faith.

Under this Safe Harbor, we commit to:

  • No Legal Action: We will not initiate or support civil or criminal legal proceedings (such as claims under computer crime or anti-circumvention laws) against researchers acting in good faith under this policy.
  • Waiver of DRM/Protection Claims: We waive claims regarding the circumvention of technical protection measures (e.g., API authentication, app reverse-engineering, firmware encryption) where necessary for research conducted under this policy.
  • Third-Party Defense: If a third party or law enforcement agency initiates legal action against you for research conducted under this policy, we will publicly declare that your research was conducted in compliance with our CVD policy.

Good Faith Criteria:

Safe Harbor protections apply only when research avoids:

  • Privacy violations, account takeover, or data exfiltration involving other users.
  • Destruction, modification, or disruption of cloud infrastructure, APIs, or physical hardware.
  • Extortion, ransom demands, or coupling disclosures to financial payment.
  • Creation of physical hazards (e.g., triggering thermal runaway on heating units).

Note: We do not currently operate a monetary bug bounty program.

7. Policy Contact & Maintenance

For inquiries regarding this policy, contact mailto:security@millnorway.com.

This policy is maintained in compliance with EU Regulation 2024/2847 (Cyber Resilience Act) and is accessible at Policy: https://millnorway.com/cvd-policy and via Canonical: https://millnorway.com/.well-known/security.txt