Reporting a security vulnerability Comodule builds connected hardware and software for light electric vehicles. If you believe you have found a security vulnerability in any Comodule product or service, we want to hear about it.
Contact: security@comodule.com
We accept reports in English and Estonian.
How to report Please include, as far as you can:
What the issue is, and what an attacker could do with it. Which product, domain, app version or module is affected. The steps needed to reproduce it, including any proof of concept. Your name or handle, if you would like to be credited. What you can expect from us We will acknowledge your report within 5 business days. We will tell you our assessment and intended course of action within 10 business days. We will keep you informed until the issue is resolved, or explain why we will not act on it. If you would like credit for the finding, we are glad to give it once the issue is fixed. We do not operate a paid bug bounty programme.
Scope In scope:
Comodule IoT modules and their firmware, including a module you own. The Comodule cloud backend and its APIs. The Comodule Developer Portal (portal.comodule.com). The Comodule Companion App (Android and iOS) and the Comodule SDK. comodule.com and its subdomains. Out of scope:
Automated scanner output with no demonstrated, exploitable impact. Missing security headers, cookie flags or TLS configuration with no practical impact. Social engineering or phishing against Comodule staff, and physical attacks on Comodule premises. Denial of service, volumetric or resource exhaustion testing. Vulnerabilities in third-party services we do not operate. Attacks against modules, vehicles or accounts that are not your own. What we ask of you Give us a reasonable opportunity to fix the issue before disclosing it publicly. We ask for 90 days from your report. Do not access, modify or delete data belonging to other users. If you encounter personal data, stop and tell us. Do not degrade or interrupt our services, or the vehicles our customers depend on. Test only against your own account, your own vehicle, or your own module. Safe harbour If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you. If a third party brings legal action against you for research conducted in good faith under this policy, we will make this authorisation known.
This policy does not grant permission to act in any way inconsistent with applicable law.
Our own reporting obligations Comodule is subject to the EU Cyber Resilience Act. Where a reported vulnerability is being actively exploited, we are required to notify the relevant authorities within statutory deadlines. Reporting to us does not remove that obligation, and we may have to share details of your report with ENISA or a national CSIRT.
Last updated: 10 September 2026