Vulnerability Report

Report a Security Vulnerability

Inventronics is committed to the security of its products and services. If you believe you have found a security vulnerability in an Inventronics product, service, or application, we would like to hear from you.

How to report

Please use the vulnerability reporting form below, or send your report to support@inventronicsglobal.com.

To help us assess your report, please include where possible:

  • Product name, type or ident code, and firmware/software version
  • Description of the issue and the affected functionality
  • Steps to reproduce
  • Potential impact
  • Supporting evidence (screenshots, log files, packet captures)
  • Any indication that the issue is being actively exploited
  • Your contact details

What happens next

StepWhat to expect
1. ReceiptYou receive an automated confirmation with a reference number. This confirms receipt only — it is not an assessment of the reported issue.
2. ReviewYour report is reviewed by the responsible team. We aim to provide an initial substantive response within 5 business days.
3. Follow-upWe may contact you if we need further information to reproduce or assess the issue.
4. ResolutionWhere a vulnerability is confirmed, we develop corrective or mitigating measures and inform affected users as required.
5. FeedbackWe inform you of the outcome of our assessment.

Please quote your reference number in any further correspondence.

Coordinated disclosure

We ask that you allow us a reasonable period to investigate and, where necessary, provide a fix before any public disclosure, and that you coordinate the timing and content of any publication with us.

Once a vulnerability has been resolved, we disclose information about it and the available corrective measures. Publication may be delayed where the security risk of early publication outweighs the benefit, until users have had the opportunity to update.

Responsible research

When investigating potential vulnerabilities, please:

  • Avoid any action that could disrupt services, degrade availability, or affect the safety of installations
  • Avoid accessing, modifying, deleting, or disclosing third-party data
  • Limit testing to systems and products under your own control or for which you have authorisation
  • Comply with all applicable laws

Inventronics will not pursue legal action against researchers who report vulnerabilities in good faith and in compliance with this policy.

Inventronics does not operate a bug bounty programme and does not offer financial compensation for vulnerability reports.

Scope

This policy covers products and services placed on the market by Inventronics, including LED drivers and lighting control components with digital elements, connected lighting systems, sensors, gateways and controllers, and associated applications and cloud services.

Third-party products not manufactured or operated by Inventronics are out of scope. Where a vulnerability originates in a third-party or open-source component integrated into our products, we handle it within our vulnerability handling process and, where appropriate, report it to the component supplier.

Data protection

Personal data provided in a report is processed solely to handle and respond to that report, in accordance with applicable data protection law. See our privacy statement for details.

Contact: support@inventronicsglobal.com

Version 1.0 — September 15, 2026

Potential Cybersecurity Vulnerability Report

Preferred contact method

Information on affected product / service

Vulnerability / Incident summary

Potential CRA relevance


Issue type



Impact and exploitation information

Potential impact*




Severity estimation*




Is active exploitation known or suspected?


Is a workaround known?


Is this related to an already known vulnerability?


Has the issue been publicly disclosed?


Supporting attachments

Attachments provided





    Allowed file types: PDF, TXT, CSV, XLS, XLSX, ZIP, JPG, JPEG, PNG, GIF, WEBP, LOG, JSON, XML, INI, CFG, CONF, PCAP, PCAPNG, CAP, DMP. Maximum 10 MB per file.

    Reporter consent and communication