Responsible Disclosure
Amplex Denmark ApS develops and maintains hardware and software products for street lighting management, including the gridCPU-LTE, gridCPU-LoRa, gridDOT and Ams product families, the GridLight, MeterMind, GreenWise, TravelTime, AirQuality and CheckMarks platforms, and the GridLight Service Link mobile app.
We take the security of our products seriously. If you have discovered a potential security vulnerability in any of our products or services, we encourage you to report it to us responsibly. We commit to working with you to understand and address the issue promptly.
How to report
Send your report to: security@amplex.dk
We recommend encrypting sensitive reports using our PGP key:
Key ID: [D7DE97625A210FD9] Fingerprint: [7040 E298 EAF7 4F82 20F8 1408 D7DE 9762 5A21 0FD9] Download here.
Please include in your report: — A description of the vulnerability and the affected product or component — Steps to reproduce the issue — Your assessment of the potential impact — Any proof-of-concept code or screenshots (if applicable) — Your preferred contact details for follow-up.
What to expect from us
We will acknowledge receipt of your report within 5 business days.
We will provide an initial assessment within 20 business days, including whether we can reproduce the issue and our proposed timeline for a fix.
We aim to resolve confirmed vulnerabilities within 90 days of the initial report. Where this is not possible, we will communicate the reason and an updated timeline.
We will credit you in our security advisory when the issue is resolved, unless you prefer to remain anonymous.
We ask that you do not publicly disclose the vulnerability until we have had the opportunity to address it and coordinate a disclosure date with you.
Scope
This policy covers all Amplex Denmark ApS products and services, including: — Hardware: gridCPU-LTE, gridCPU-LoRa, gridDOT-LoRa, gridDOT-LTE, gridDOT-Radar, AmsCPU, AmsCPU-IO, AmsCPU-4G, AmsCPU-IO-4G, AmsSwitch, AmsBattery, AmsCurrent, AmsRS485 — Server software: GridLight, MeterMind, GreenWise, TravelTime, AirQuality, CheckMarks — Mobile app: GridLight Service Link
Issues in third-party components used by our products are in scope if they affect the security of our products. We will pass reports relating to underlying third-party components to the relevant vendor.
Out of scope
The following are outside the scope of this policy: — Denial of service attacks against our infrastructure — Physical attacks against hardware in the field — Social engineering of Amplex staff — Automated scanning that generates excessive traffic.
Legal
Amplex Denmark ApS will not pursue legal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy. We ask that you avoid accessing, modifying or deleting data beyond what is necessary to demonstrate the vulnerability.
