Skip to main content

Vulnerability Disclosure Policy

Last updated: September 2026

CoolR Group, Inc. ("CoolR," "we," "us") is committed to keeping our hardware, connected platform, and services secure. We value the work of independent security researchers and the wider security community in helping us find and fix vulnerabilities before they can be exploited.

This policy explains how to report a security vulnerability to us, what you can expect from us in return, and the ground rules for responsible testing.

Scope

This policy covers:

  • CoolR hardware devices, including our connected cameras, and their firmware
  • The CoolR connected intelligence platform, including our web application and dashboards
  • CoolR APIs and integrations
  • Our public websites, including docs.coolr.ai and coolr.ai

If you're not sure whether something is in scope, report it anyway — we'd rather review a borderline report than miss a real issue.

Out of scope:

  • Denial-of-service (DoS/DDoS) testing against our infrastructure or a customer's live deployment
  • Physical tampering with, or removal of, hardware installed at a customer or retail site without that site's explicit permission
  • Social engineering, phishing, or physical-security testing against CoolR staff or customers
  • Automated vulnerability scanning that generates high volumes of traffic without prior coordination with us
  • Testing that could disrupt a retailer's or brand partner's live operations (e.g., a cooler with a connected camera in active use in a store)

How to Report a Vulnerability

Email support@coolr.ai with the subject line Security Vulnerability Report.

Please include as much of the following as you can:

  • A description of the vulnerability and its potential impact
  • The product, device model, platform component, or URL affected
  • Step-by-step instructions to reproduce the issue
  • Any supporting evidence (screenshots, logs, proof-of-concept code)
  • Your contact details, so we can follow up and credit you appropriately

Please do not include sensitive customer or business data in your report beyond what's strictly necessary to demonstrate the issue.

What You Can Expect From Us

MilestoneTarget
Acknowledgment of your reportWithin 2 business days
Initial assessment and severity triageWithin 10 business days
Regular status updatesAt least every 30 days until resolved
Remediation and coordinated disclosureWithin 90 days of confirmation

The 90-day target may be extended for issues requiring a firmware update or hardware rework across our installed device fleet, or where coordination with a third-party component vendor is required. If we need more time, we will tell you why and give you a revised estimate.

We will keep you informed throughout the process and will notify you when the issue is resolved.

Why these timelines look different from other deadlines you may have seen. Under the EU Cyber Resilience Act, CoolR is separately required to notify ENISA and our coordinating national CSIRT within 24 hours of becoming aware that a vulnerability is being actively exploited, or that a severe incident has occurred, with a fuller notification due at 72 hours. That is a regulatory reporting obligation aimed at alerting authorities quickly to live threats — it is not a remediation deadline, and it runs alongside, not instead of, our work on your report. If your report indicates the vulnerability is already being exploited, we will trigger that regulatory notification immediately in parallel with the assessment and remediation timeline above; you do not need to do anything differently, and we will still keep you updated throughout.

Coordinated Disclosure

We ask that you give us the opportunity to investigate and remediate a vulnerability before disclosing it publicly. We commit to:

  • Working with you on a mutually agreed disclosure timeline
  • Crediting you (if you wish) once the issue is resolved
  • Not pursuing legal action against researchers who follow this policy in good faith

Please do not disclose the vulnerability publicly, to third parties, or on social media until we've confirmed a fix is available or the agreed disclosure date has passed — whichever is sooner.

Safe Harbor

If you make a good-faith effort to comply with this policy, we will consider your research to be authorized. We will not pursue civil or criminal legal action against you, and will work with you to understand and resolve the issue quickly.

This safe harbor applies only to research conducted in accordance with this policy — including staying within scope, avoiding data destruction or privacy violations, and reporting through the channel above rather than exploiting or publicly disclosing the issue first. It does not extend to conduct that violates applicable law, targets other users or organizations, or accesses data beyond what is necessary to demonstrate the vulnerability.

Our Regulatory Commitment

This policy supports CoolR's obligations under the EU Cyber Resilience Act (Regulation (EU) 2024/2847), which requires manufacturers of connected products to maintain a coordinated vulnerability disclosure process and a public point of contact for security researchers. We review and update this policy as our compliance program matures.

Questions

For anything not covered here, contact us at support@coolr.ai.


This policy may be updated from time to time. It does not create any contractual rights or obligations, and does not modify any other agreement between you and CoolR.