Security & Vulnerability Disclosure
Last updated: September 9, 2026
Kode makes connected hardware, and we want to know when something is wrong with it before anyone gets hurt by it. If you have found a security issue in a Kode product or service, this page tells you how to reach us, what we will do, and what you can expect in return.
1. How to report a vulnerability
Email [email protected] with "Security" in the subject. The mailbox is read every working day and security reports are passed straight to the people who can act on them. The machine-readable version of this contact is published at /.well-known/security.txt (RFC 9116). We read English and Spanish.
Please include, as far as you can:
- Which product or service is affected: the Kode Dot (hardware revision and kodeOS version, shown in the device settings), an app from the marketplace, the Kode mobile app, kode.diy, apps.kode.diy, api.kode.diy, cloud.kode.diy or docs.kode.diy.
- Steps to reproduce, or a proof of concept.
- What impact you believe it has.
- Whether you want to be credited when we publish the fix, and under what name.
Do not send us personal data of other people. If you came across it while researching, tell us that you did, delete it, and describe how it was reachable.
2. What happens next
- Acknowledgement within 3 working days. A person replies, confirms we received the report and gives you a reference.
- Triage within 10 days. We reproduce the issue, rate its severity and tell you whether we consider it a vulnerability, what we intend to do and roughly when.
- Fix. We aim to ship a fix for confirmed vulnerabilities within 90 days of the report, and much sooner when the issue is severe or exploitation is likely. Firmware fixes reach the Kode Dot through the same free update path every owner already uses (the marketplace and the Kode app); service fixes are deployed by us.
- You stay informed. We tell you when the fix ships and, if you asked for it, credit you in the advisory.
3. Coordinated disclosure
We ask that you give us the chance to fix the problem before making it public: please keep the details private until a fix is available or until 90 days have passed since your report, whichever comes first. If we need longer for a good reason (a hardware constraint, a fix that depends on a third party) we will say so and agree a date with you rather than go quiet.
When a fix ships we publish a short advisory describing the issue, the affected versions and the fixed version, and we notify affected users through the product itself when the risk warrants it.
4. Safe harbor
Security research carried out in good faith and within these rules is welcome. We will not take legal action against you, nor refer you to law enforcement, for research that:
- only touches devices, accounts and data that belong to you or that you have explicit permission to test;
- does not degrade the service for other people (no denial of service, no spam, no brute-forcing other users' accounts);
- does not access, modify or exfiltrate other people's data beyond the minimum needed to demonstrate the issue;
- does not involve social engineering of our staff or users;
- follows the disclosure terms above.
If you are unsure whether something is covered, ask first at the same address.
5. Scope
In scope:
- The Kode Dot hardware and its operating system (kodeOS).
- Apps published by Kode on the marketplace.
- The Kode mobile app for iOS and Android.
- kode.diy, apps.kode.diy, api.kode.diy, cloud.kode.diy, docs.kode.diy and the other services under kode.diy that we operate.
Out of scope:
- Third-party services we rely on (for example the Shopify checkout at checkout.kode.diy, GitHub, Google or Apple sign-in). Report those to the provider; tell us too if a Kode integration makes them worse.
- Apps published by community members. We will pass your report to the author and remove the app if needed.
- Reports from automated scanners without a demonstrated impact, missing best-practice headers with no exploit, or issues that require physical access to an unlocked device.
6. Security support period
Every Kode product receives free security updates, without undue delay, for at least five years from the day it is first made available to customers. For the Kode Dot this means security updates until at least 31 December 2031. If we ever have to end support for a product, we will announce the date here and on the product page at least twelve months in advance.
Updates are delivered through the marketplace and the Kode app over Bluetooth, Wi-Fi or USB, at no cost.
7. Our legal obligations
Kode products fall under the EU Cyber Resilience Act, Regulation (EU) 2024/2847. Under its Article 14, when we become aware that a vulnerability in one of our products is being actively exploited, or of a severe incident affecting a product's security, we notify the designated national CSIRT and ENISA: an early warning within 24 hours, a fuller notification within 72 hours, and a final report once a fix is available. We also inform affected users without undue delay, with the steps they can take in the meantime. Your report may be what starts that clock, which is one more reason we take every report seriously.
8. Who we are
KODE DIY SL (NIF B21903190), Carrer d'Albuixech 8, Piso 4 Puerta 13, 46019 Valencia, Spain. [email protected].