Vulnerability Disclosure Policy
Metis takes the security of its products and services seriously. We welcome reports from security researchers and will work with you to understand and resolve issues quickly.
How to report a vulnerability
If you believe you have found a security vulnerability in one of our products or services, please contact us using the details below.
Email: security@metis.tech
To help us triage and resolve the issue as fast as possible, please include:
- The product, service, or component affected (and version, if known).
- A description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce the issue.
- Any proof-of-concept code, screenshots, or logs.
- How we can contact you for follow-up questions.
Our commitment to you
We will not pursue or support legal action against researchers who, in good faith, discover and report vulnerabilities in accordance with this policy. Specifically, if you:
- Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services;
- Only access, store, or disclose the minimum amount of data necessary to demonstrate the issue;
- Give us a reasonable time to resolve the issue before disclosing it publicly; and
- Do not exploit the issue beyond what is necessary to confirm it,
then we will consider your research authorised, and we will work with you to understand and resolve the issue quickly.
What to expect from us
Our response timeline
- Acknowledgement: we will confirm receipt of your report within 3 business days.
- Initial assessment: we will provide an initial assessment within 10 business days.
- Progress updates: we will keep you informed of our progress toward a fix.
- Resolution: we aim to resolve confirmed, valid issues within 90 days, depending on severity and complexity.
We follow a coordinated vulnerability disclosure approach. We will coordinate the timing of any public disclosure with you, and — where you wish — credit you for your discovery.
Scope
In scope
- Metis Web Portals (*.metis.tech)
- Metis IoT Devices
Out of scope
Third-party services we do not control, denial-of-service attacks, social engineering of our staff, physical attacks, automated scanner output without a demonstrated impact.
What we ask of you
- Do not access, modify, or delete data that does not belong to you.
- Do not degrade, disrupt, or perform denial-of-service testing against our services.
- Do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it and we have agreed on timing.
- Comply with all applicable laws.

