Security at WPITCOM – Reporting Vulnerabilities
Protecting our customers’ data and the integrity of our platforms is our highest priority. Even so, no software is entirely free of flaws. That is why we value the support of security researchers who alert us to potential vulnerabilities in our products and services.
Our Approach: Coordinated Disclosure
We work in partnership with the security community. If you discover a vulnerability, please report it to us confidentially first. This allows us to fix the issue before any information becomes public.
Scope
This policy applies to the following products and systems of WPITCOM S.A.:
Online services operated by WPITCOM
- the website wpitcom.com,
- the cloud platform WPITCOM Signage Manager 3,
- the WPITMEDIACLOUD platform.
WPITCOM hardware and software
- hardware players (e.g. the DSP-xxx-A/L hardware family), including operating system, firmware and player software,
- people counters and sensors distributed by WPITCOM,
- other devices distributed or developed by WPITCOM, as well as software for Android and Linux players.
You may only examine hardware and the software running on it using devices that you lawfully own or that we have provided to you for testing purposes. On your own devices, analysis of the firmware and hardware interfaces is also permitted. Please note that opening or modifying a device may affect its warranty.
Out of scope:
- Devices, installations and networks of our customers. This applies even where WPITCOM hardware or software is in use there, for example players or people counters in stores, restaurants and hotels, or on-premise installations.
- Third-party systems such as hosting or cloud providers.
Testing these systems requires the consent of the respective operator. If you suspect a vulnerability at a customer site, please report it to us without testing the device or system any further.
Note on people counters: When examining a device that processes camera or sensor data, do not capture any individuals who have not given their consent. If you come across image or movement data of third parties, the rules on personal data apply.
Rules of Engagement
Please observe the following during your research:
- Access data only to the extent strictly necessary to demonstrate the vulnerability. Do not copy, modify, delete or share any data.
- If you encounter personal data, stop testing and notify us immediately.
- Do not impair the availability of our services. Denial-of-service testing, spam and automated mass requests are not permitted.
- Social engineering directed at employees or customers, as well as phishing, is not permitted. Physical tampering is only allowed on your own devices, not on devices at customer sites or on our premises.
- Do not exploit a vulnerability beyond what is needed to demonstrate it, and do not establish persistent access.
- Report the vulnerability promptly after discovering it.
- Do not publish or share details until the vulnerability has been fixed and we have agreed to disclosure.
How to Reach Us
What to Include in Your Report
The more precise your report, the faster we can respond. Where possible, please describe:
- which system, device or URL is affected and what type of vulnerability it is,
- for hardware: device type and firmware or software version,
- how to reproduce the issue step by step (screenshots or videos are welcome),
- a proof of concept, if available,
- your assessment of the potential impact,
- how we can reach you for follow-up questions.
What You Can Expect from Us
Acknowledgement of your report
Initial technical assessment
Regular updates on remediation progress
Public credit by name in our news after a successful fix, if you wish
Legal Assurance (Safe Harbor)
If you act in good faith and comply with the rules of this policy, WPITCOM S.A. commits to the following:
- We will not file a criminal complaint or request prosecution against you.
- We will not pursue civil claims against you.
- We will consider your research authorized, provided it stays within the scope defined above.
Please note: This assurance binds WPITCOM S.A. only. We cannot waive the rights of third parties, such as our customers. Nor can we prevent authorities from opening investigations on their own initiative. Should a third party take legal action against you, we will, upon request, confirm that your conduct complied with this policy.
If you are unsure whether a planned investigation complies with this policy, please ask us beforehand at security@wpitcom.com.
Legal Obligations
WPITCOM’s statutory reporting and notification obligations remain unaffected by this policy. This applies in particular to obligations under the EU General Data Protection Regulation (GDPR) towards our customers and supervisory authorities.
Recognition
We do not currently offer a bug bounty program with financial rewards. All the more, we thank everyone who reports valid vulnerabilities to us and thereby contributes to the security of our customers.
Governing Law
This policy is governed by the laws of the Republic of Guatemala. Mandatory provisions of the country in which the research is carried out remain unaffected.
Non-Security Inquiries
For general product feedback or technical support, please contact our service team:
