Media Tech Smart Control Ltd. (“DOMEX”, “we”, “our”) values the security of our smart home devices, controllers, cloud platform (PCC – Professional Cloud Configuration), mobile applications and related services (collectively: the “Services”). This policy explains how security researchers, customers and partners may responsibly report vulnerabilities.
1. Our Commitment
We commit to investigating legitimate vulnerability reports, responding in a reasonable timeframe, working to remediate verified security issues, and coordinating disclosure when appropriate. We appreciate responsible security research that helps protect our users.
2. Reporting a Vulnerability
Please report vulnerabilities to security@domex.life. Include if possible: a description of the issue; affected product / firmware / app version; steps to reproduce; proof of concept (logs, screenshots, video); and your contact details. We will acknowledge receipt as soon as reasonably practicable.
3. Acceptable Research
The following actions are considered authorized when performed in good faith: testing devices you own or are authorized to test; non-destructive testing; avoiding access to other users’ data; and coordinating disclosure with DOMEX before publication.
4. Prohibited Activities
- Accessing accounts, homes, or systems without permission
- Intercepting data belonging to other users
- Physical tampering in occupied installations
- Service disruption or denial-of-service attacks
- Social engineering or phishing
- Public disclosure before coordinated resolution
5. Safe Harbor
DOMEX will not initiate legal action against individuals who act in good faith, follow this policy, avoid privacy violations, and provide reasonable time for remediation. This safe harbor applies only to activities consistent with this policy and applicable law.
6. Disclosure Process
Our typical process: acknowledge report → validate vulnerability → develop mitigation → coordinate disclosure → release update if necessary. We may request confidentiality until users are protected.
7. Out of Scope
Generally not considered vulnerabilities: issues requiring unrealistic attack conditions; theoretical attacks without real impact; missing best-practice headers on marketing pages; and third-party service vulnerabilities outside DOMEX control.
8. Rewards
DOMEX currently does not operate a public bug bounty program unless announced separately. We may acknowledge responsible researchers at our discretion.
9. Limitation of Liability & No Warranty
This policy is provided solely as a mechanism for responsible disclosure and does not create any contractual relationship between the reporter and DOMEX. DOMEX makes no guarantee regarding remediation timelines, acceptance of submissions, or public acknowledgement. Submission of a vulnerability report does not grant authorization to access, test, or modify any system beyond the scope defined in this policy. DOMEX shall not be liable for any costs, damages, or losses incurred by the reporter in connection with testing or disclosure activities.
10. Legal
Testing must comply with all applicable laws and regulations. Nothing in this policy authorizes illegal activity.
11. Contact
Security Team – DOMEX · Media Tech Smart Control Ltd. · Flamingo 4, Be’er Yaakov, Israel · security@domex.life