SECURITY

GOQUAL Vulnerability Reporting and Support Policy

GOQUAL Inc. (“the Company”) is committed to protecting our customers' daily lives and providing a safe environment for the IoT ecosystem. This page sets out how we receive, validate and remediate security vulnerabilities in our services, and our security update policy.

If immediate action is required — personal data exposure, account takeover or service outage — please mark the email subject with [긴급] (Urgent).

1.Vulnerability Reporting and Disclosure Policy

1-1.Purpose and Scope

  • PurposeTo define a standard procedure for receiving, validating and remediating security vulnerabilities in our services promptly and safely.
  • In scopeAssets owned, managed and operated directly by the Company.
    • Our official website (https://www.goqual.com)
    • The official “Hejhome” mobile app for iOS and Android
  • Out of scopeDiscontinued products, DDoS attacks, infrastructure load generated by automated scanning, third-party platforms, third-party services, and partner systems.

1-2.How to Report

  • Reporting channelsecurity@goqual.com (RFC 9116 file: https://www.goqual.com/.well-known/security.txt)If immediate action is required — personal data exposure, account takeover, service outage — please include [긴급] (Urgent) in the email subject.
  • Required information
    • Your name (or an identifiable handle) and contact details we can reply to
    • Target details: product/model name, S/N, LOT number, app version, firmware version, URL or API path
    • Vulnerability type and expected impact
    • Reproduction steps: detailed description, PoC script, request/response samples, video or screenshots
    • Date and time of discovery, and any actual impact observed (e.g. exposure of personal data or accounts, service disruption)

De-identification — reports must not contain other users' personal data, video, audio or account information. Where inclusion is unavoidable for validation, it must be masked or otherwise de-identified before submission.

1-3.Handling Process

  • AcknowledgementWe acknowledge receipt within 5 business days.
  • Impact assessmentWe assess reproducibility, scope of impact, exploitability and overall risk level.
  • Remediation deadlineConfirmed vulnerabilities are remediated within a maximum of 180 days from the date of receipt.This may be extended depending on complexity and third-party cooperation; if so, we will share an expected timeline.
  • Duplicate reportsIf a report duplicates a known or in-progress issue, we will notify you separately.
  • Rights in submitted materialFor all material submitted with a report, the Company holds a perpetual, royalty-free right to reproduce, modify, distribute and use it for validation and remediation purposes.

1-4.Reporter Obligations (Prohibited Conduct)

Testing must be limited to the minimum necessary to confirm a vulnerability. The following conduct is strictly prohibited.

  • No access to others' personal data or footageAccessing, viewing, copying, storing or exfiltrating another person's personal data, video/audio data, or account information.If you access such data incidentally, stop immediately, notify us, and destroy any collected material.
  • Data destruction and malware distributionAltering, deleting or destroying data, or installing or distributing malicious programs.
  • Causing service disruptionDoS/DDoS attacks, excessive automated scanning, infrastructure load testing, or other conduct that degrades availability.
  • Social engineering and physical intrusionPhishing or deception targeting employees or customers, and physical intrusion into data centres or offices.
  • Extortion and improper demandsUsing a vulnerability for further intrusion, privilege escalation or lateral movement, and demanding money, virtual assets, employment or other consideration, or making threats.

1-5.Safe Harbor

The Company will not pursue civil or criminal action for vulnerability research and reporting carried out in good faith, within the scope and by the methods set out in this policy.

As a limitation, this safe harbor applies only to the exercise of the Company's own rights. It does not affect infringement of third-party rights, nor law enforcement by investigative or other state authorities, and it does not apply to conduct outside the scope of this policy.

1-6.Non-disclosure and Coordinated Publication

As a rule, reporters should not disclose vulnerability details publicly before our security patch is complete. After the patch, publication of your analysis is possible once the timing, scope and related matters have been agreed in advance with the Company (security@goqual.com).

To recognise reporters who follow this policy, the Company may credit your name (or handle) in acknowledgement when a significant patch is completed.

1-7.Governing Law and Jurisdiction

This policy is governed by the laws of the Republic of Korea. Any dispute shall be submitted to the court of first instance having jurisdiction under the Korean Civil Procedure Act.

Conduct outside the scope and methods set out in this policy is not protected and may give rise to civil or criminal liability under applicable law, including the Act on Promotion of Information and Communications Network Utilization and Information Protection and the Personal Information Protection Act.

2.Security Update Support Policy

2-1.Support Period

We guarantee essential security updates on the following basis in order to mitigate risk.

  • IoT devicesEssential security patches are provided for at least 1 year after discontinuation (end of sale).
  • Mobile appsPatches are provided in line with new releases of the latest iOS and Android operating systems.

2-2.Patch Delivery Process

When a vulnerability is identified, we deliver security updates through the following stages under our internal criteria.

  1. Stage 1

    Identify the vulnerability

  2. Stage 2

    Assess its impact

  3. Stage 3

    Develop and verify the remediation patch

  4. Stage 4

    Distribute over the air (OTA) and notify users

2-3.Regular Security Updates

Throughout the product lifecycle we carry out regular monitoring to protect against threats not yet identified, and deliver regular security updates on that basis.

If you have any questions about this policy, please contact our security channel at security@goqual.com.

This English text is provided for convenience. In case of any discrepancy, the Korean version prevails.