KeldCo Product Security

Product Security & Vulnerability Disclosure

This page provides KeldCo consumers, security researchers, and regulators with product safety and security support information, prepared in accordance with the UK Product Security and Telecommunications Infrastructure Act 2022 (PSTI), ETSI EN 303 645 (Cyber Security for Consumer Internet of Things), and equivalent obligations in the other markets in which KeldCo products are sold.

Policy owner: Keld & Co Pty Ltd (ABN 85 656 435 568) Last updated: [[ TBC — DD Month YYYY ]] Version: 1.0
01

Product security update support

To ensure the cybersecurity of your products throughout their lifecycle, KeldCo commits to providing ongoing security updates for the products listed below. Support coverage is defined by the date in the “Defined support period” column; prior to this date, we will release necessary security updates to address identified vulnerabilities.

Product model(s) Product name Defined support period (expiration date)
[[ TBC — model numbers ]] Solar Cam Pro 3.0
Solar security camera, Wi-Fi
[[ TBC — DD Month YYYY ]]
[[ TBC — model numbers ]] Door Nerve
[[ TBC — product description ]]
[[ TBC — DD Month YYYY ]]
[[ TBC — model numbers ]] Doormate
Video doorbell
[[ TBC — DD Month YYYY ]]
[[ TBC — model numbers ]] Glass Eye
Window / glass-mount security camera
[[ TBC — DD Month YYYY ]]
[[ TBC — model numbers ]] Home Guardian
Indoor security camera
[[ TBC — DD Month YYYY ]]
[[ TBC — model numbers ]] Lumis Pro
Hardwired 240V floodlight camera, 24/7 recording
[[ TBC — DD Month YYYY ]]
Note: The support period for each product begins from the date the product is first made available in the applicable market. Security updates may be delivered via over-the-air firmware upgrade, the KeldCo mobile application, or other means. Users are advised to keep their products connected to the internet and to allow automatic updates to ensure timely receipt of security patches. Accessories such as Micro TF memory cards contain no firmware and are not within the scope of the security update lifecycle. When a product approaches end-of-support, we will publish notice on this page at least 12 months in advance.
02

Security vulnerability reporting policy

KeldCo places great importance on the security of our products and encourages security researchers, customers, and the wider community to follow the principle of responsible disclosure and report any security vulnerabilities that have been discovered. Our vulnerability handling process adheres to internationally recognised standards, including ISO/IEC 29147 (Vulnerability disclosure) and ISO/IEC 30111 (Vulnerability handling processes).

If you believe you have identified a security vulnerability in any KeldCo product, firmware, mobile app, cloud service (including KeldCloud), website, or associated infrastructure, please report it to us using either of the channels below. We welcome coordinated disclosure and will not pursue legal action against researchers acting in good faith under this policy.

Dedicated security email
Submission portal
Monitoring hours
Australian business hours (AEST)

Please include as much detail as possible: affected product and firmware version, description of the issue, steps to reproduce, potential impact, and any proof-of-concept material. Reports may be submitted in English.

03

Response SLA & progress commitments

KeldCo commits to the following response times for every valid security report received via cyber@keldco.com or the submission portal below.

48 hours
Initial acknowledgement of receipt
5 business days
Initial triage & severity assessment
Every 7 days
Written progress update to reporter until resolution
30 days
Target remediation for Critical severity issues
60 days
Target remediation for High severity issues
90 days
Target remediation for Medium / Low severity issues

Where a remediation cannot be delivered within the target window (for example, where third-party component fixes are required), we will notify the reporter in the next scheduled progress update, explain the reason for the delay, and provide a revised target date.

04

Complete vulnerability handling process

Every report follows the same structured lifecycle, from receipt through to public disclosure.

  1. Receipt & acknowledgement

    Report is received at cyber@keldco.com or via the submission portal. A case ID is assigned and an acknowledgement is sent to the reporter within 48 hours.

  2. Triage & reproduction

    Within 5 business days, our security lead validates the report, reproduces the issue where possible, and assigns a preliminary CVSS v3.1 severity rating (Critical / High / Medium / Low).

  3. Impact assessment

    We determine which products, firmware versions, cloud components, and customer populations are affected, and confirm whether the issue is already known or has an existing CVE.

  4. Remediation development

    Our engineering and manufacturing partners develop a fix. Where a third-party component is involved (e.g. an upstream SDK), we coordinate directly with the upstream vendor.

  5. Testing & validation

    The proposed fix is tested against the original reproduction steps and regression-tested against affected product lines before release.

  6. Coordinated release

    A firmware or software update is released via over-the-air update, the KeldCo app, or a security advisory, depending on the product. The reporter is notified in advance where possible.

  7. Public disclosure & CVE assignment

    Once the fix has been deployed and customers have had a reasonable opportunity to update (typically 30 days post-release), a disclosure is published in the Historical Vulnerability Archive below, including CVE number, risk rating, impact, and remediation timeline.

  8. Post-incident review

    Every closed report is reviewed internally to identify root cause and any process improvements to prevent recurrence.

05

Historical vulnerability archive

All publicly disclosed vulnerabilities affecting KeldCo products are listed below, together with their CVE number, risk rating, impact scope, and remediation timeline.

CVE number Disclosed Risk Affected products Impact scope Remediation time
No vulnerabilities have been publicly disclosed to date. This table will be updated as disclosures are published in accordance with the process above.
06

No universal default passwords

In accordance with the UK PSTI Act and ETSI EN 303 645 provision 5.1, KeldCo products do not use universal, factory-preset, or easily guessable default passwords. During first-time setup, every user is required to create a unique KeldCo account and set a strong password before the product can be operated or connected to the KeldCo cloud service.

Passwords are subject to the following minimum requirements:

  • Minimum length of 8 characters;
  • A combination of letters and numbers (special characters recommended);
  • Cannot match the account username or email address;
  • Cannot be a commonly compromised password (checked against known-breached password lists at time of creation);
  • Users are prompted to change their password if suspicious activity is detected on their account.

Product pairing codes, QR codes, and device identifiers printed on packaging are unique to each individual unit and are not usable as passwords for the KeldCo cloud service or the mobile application.

07

Declaration of Conformity

KeldCo confirms that the products listed in Section 01 above comply with the security requirements set out in the UK Product Security and Telecommunications Infrastructure Act 2022 (PSTI) and the security provisions of the benchmark standard ETSI EN 303 645 — Cyber Security for Consumer Internet of Things: Baseline Requirements.

A Statement of Compliance (SoC) and complete technical documentation have been prepared and are maintained for each in-scope product line, and are retained for the minimum period required by law. As required by the Act, KeldCo will provide these documents for review upon request by a regulatory authority or an authorised evaluation body.

For requests relating to the Statement of Compliance or technical documentation, please contact cyber@keldco.com.

08

Security contact

For any question relating to this policy, product security, or an in-flight disclosure, the following contact applies.

Contact person Josh Salkeld
Role Founder & CEO, KeldCo
Primary email cyber@keldco.com
CC email cyber@keldco.com
09

Vulnerability submission portal

Use the form below to report a security issue directly to our security team. Fields marked with an asterisk are required. On submission, the form will open your default email client with the details pre-filled and addressed to cyber@keldco.com.

Submitting this form will open your email client with the report pre-filled to cyber@keldco.com. If your browser cannot open a mail client, please email your report directly to cyber@keldco.com. Do not include sensitive personal information beyond what is necessary to reproduce the issue.