Security
Reporting a security flaw
All the watch’s code is public. So we expect people to look for flaws in it, and we want to know what they find. This page says how to tell us and what we do next.
What is in scope
- The firmware of the watch and its protocol, Cobalt Link.
- The Cobalt Agent and Cobalt Agent Dev apps.
- The online gateway of the Pro and Max plans.
- This website.
How to report
Write to jean@cobalt-watch.com, in English or in French. Please don’t open a public issue for a flaw.
Tell us:
- what you found, and on which version;
- how to reproduce it;
- what an attacker could do with it.
We don’t have a PGP key yet. If you want one before sending the details, ask and we will create one.
What we do, and when
- We acknowledge your report within 5 working days.
- Within 15 days, we tell you whether we confirm it and what we intend to do.
- We aim for a fix within 90 days, and we set the publication date with you.
What we promise you
If you act in good faith, keep to the scope above, don’t read or keep other people’s data, and give us a reasonable time before you publish, we will not take legal action against you.
We thank publicly the people who report a flaw, if they want us to.
Advisories and thanks
We publish our security advisories on the public repository. There are none so far, and nobody to thank yet.
Our own obligations
European law, with the Cyber Resilience Act, requires a manufacturer to report to the authorities any flaw in its products that is being actively exploited. If your report is about one, that is what we will do.