Coverage of Vulnerabilities:
This policy encompasses all vulnerabilities within Devialet's interconnected products, platforms, and controlling mobile applications, including those in firmware, mobile applications, and cloud services.
Services not explicitly listed above, such as any connected services, are beyond the scope and are not sanctioned for testing by Devialet. Furthermore, vulnerabilities detected in systems from our providers lie outside the purview of this policy and should be directly reported to the respective provider in accordance with their disclosure policy (if any). Should uncertainty persist regarding a system’s inclusion in scope, please contact us. Security researchers should refer to the external vulnerability disclosure policies of any third-party interconnected service to ascertain the authorized testing scope of said services.