Vulnerability Disclosure Policy

Last Updated: July 10, 2026


Introduction

At Uney GmbH (“Uney”, “we”, “our”, or “us”), the security of our communication, AI, UAV, mobility, and digital operations platforms is a top priority. We welcome responsible security research that helps us protect our users, our infrastructure, and the information entrusted to us.

Despite our best efforts, vulnerabilities can never be completely eliminated. When vulnerabilities are identified and exploited, they may affect the confidentiality, integrity, or availability of Uney systems and the information processed by those systems.

This Vulnerability Disclosure Policy describes:

• which Uney systems and services are in scope;

• which testing activities are authorized or prohibited;

• how to report a potential vulnerability to Uney;

• how Uney will handle vulnerability reports; and

• how public disclosure should be coordinated.

We encourage security researchers to contact us to report potential vulnerabilities in Uney products and services by following this policy.


Authorization

If you act in good faith to identify and report vulnerabilities in Uney systems, and you comply with this policy, Uney will treat your research as authorized conduct.

Uney will work with you to understand and resolve reported issues quickly. Uney will not initiate civil legal action or knowingly support a criminal investigation against researchers for legitimate, responsible security research activities conducted in accordance with this policy.

If a third party initiates legal action against a researcher for activities conducted in accordance with this policy, Uney will take reasonable steps to communicate that the research was authorized under this policy.

This authorization applies only to systems owned or operated by Uney and only to activities that comply with this policy.


Scope

This policy applies to Uney internet-facing systems, including:

• the Uney web presence;

• public IP addresses and attached services owned or operated by Uney;

• Uney-owned public APIs, web applications, mobile applications, and cloud services; and

• Uney software, platforms, and services expressly listed below.


In-scope Uney platforms and services

Products and platforms

• KChat

• ShieldNet 360

• SkyTrack

• KinSense

• KinShield

Corporate services

• Uney corporate systems and services

• Official Uney websites and domains (including www.uney.com)

• Uney-owned corporate web applications and online services

Any service, system, application, domain, API, infrastructure, or environment not expressly listed above is excluded from scope unless Uney provides written authorization before testing.

Vulnerabilities found in third-party systems, cloud providers, SaaS platforms, marketing platforms, helpdesk platforms, status pages, or other vendor-operated services are excluded from this policy and should be reported directly to the relevant vendor under that vendor’s own vulnerability disclosure policy, if available.


Guidelines

While carrying out security research, you must:

• act in good faith and only perform testing necessary to identify and demonstrate the vulnerability;

• use only harmless exploits to confirm that a vulnerability is present;

• avoid accessing, copying, modifying, deleting, or exfiltrating data except where strictly necessary to demonstrate the vulnerability;

• stop testing immediately when you discover a vulnerability or encounter sensitive information;

• notify Uney as soon as possible if you access personal data, confidential information, proprietary information, trade secrets, telemetry data, UAV operational data, credentials, or other non-public information;

• avoid disclosing any vulnerability or obtained data to the public or any third party until the issue has been resolved or disclosure has been coordinated with Uney;

• delete any stored non-public data after reporting the vulnerability, unless Uney instructs otherwise for remediation or verification purposes; and

• comply with all applicable laws and regulations.

You must not perform the following actions:

• place malware, viruses, worms, Trojan horses, backdoors, or harmful code on any system;

• compromise systems in order to gain full or partial control;

• attempt to gain persistence, establish command-line access, pivot, or move laterally to other systems;

• copy, modify, delete, or destroy data;

• make unauthorized changes to any system;

• repeatedly access a system after confirming a vulnerability;

• share access to any system or vulnerability with the public or any third party;

• use access obtained from one system to attempt to access another system;

• change access rights or permissions of other users;

• use automated scanning tools without prior written authorization from Uney;

• use brute-force attacks, credential stuffing, password spraying, or similar techniques;

• conduct denial-of-service, resource exhaustion, bandwidth exhaustion, or service degradation attacks;

• conduct social engineering, phishing, vishing, smishing, spam, or unsolicited messaging;

• use designated test accounts, sandbox or simulation environments, or other testing resources provided by Uney, where available, when testing in-scope telemetry modules, firmware update mechanisms, control applications, or other UAV-related software; researchers who require automated scanning or testing outside these environments must obtain prior written authorization from Uney;

• test or attempt to compromise third-party applications, services, infrastructure, or integrations not owned or operated by Uney;

• access, modify, copy, delete, retain, or exfiltrate real Uney user data beyond what is strictly necessary to demonstrate the vulnerability;

• perform testing that may interrupt Uney operations, UAV operations, mobility systems, safety-critical workflows, or customer services; or

• publicly disclose a vulnerability before it has been resolved, before disclosure has been coordinated with Uney, or before 90 days have elapsed from the date of the initial report, whichever occurs first, unless Uney and the researcher mutually agree in writing to extend the disclosure timeline.

Sensitive information

If you inadvertently access personal data, confidential information, proprietary information, trade secrets, credentials, telemetry data, UAV operational data, financial information, medical information, or other sensitive information, you must:

• stop testing immediately;

• avoid copying, modifying, sharing, retaining, or further accessing the information, except as strictly necessary to document the vulnerability;

• notify Uney as soon as possible; and

• delete any stored non-public information after reporting the vulnerability, unless Uney instructs otherwise.


Out-of-scope findings

The following findings are generally not eligible for recognition or further action unless they demonstrate a clear and meaningful security impact:

• spam or user-generated content issues;

• social engineering techniques;

• denial-of-service or bandwidth/resource exhaustion issues;

• content injection issues without meaningful security impact;

• issues affecting only outdated browsers, operating systems, or unsupported software versions;

• bugs requiring unrealistic, highly improbable, or excessive user interaction;

• issues in third-party platforms, cloud providers, SaaS integrations, helpdesk systems, status pages, or marketing platforms;

• findings requiring physical access to devices, UAVs, facilities, or hardware;

• missing security headers without demonstrable exploitability;

• version disclosure or banner disclosure without security impact;

• self-XSS without a realistic attack scenario;

• clickjacking on pages without sensitive actions;

• reports based only on automated scanner output without validation; and

• duplicate reports or previously known issues.

Reporting a vulnerability

If you identify a vulnerability, please email your findings as soon as possible to: [email protected]

When submitting your report, please state whether you agree to your name or pseudonym being publicly acknowledged as the discoverer of the vulnerability if Uney later discloses or credits the issue.

PGP-encrypted submissions are recommended. Uney’s public PGP key is available upon request.

Reports may be submitted in plain text, rich text, HTML, or common archive formats such as .zip, .7z, or .gz. Reports should preferably be submitted in English.

To help Uney validate and resolve the issue quickly, please include:

• the affected domain, IP address, application, API, service, product, or component;

• a clear description of the vulnerability;

• exact steps to reproduce the issue;

• a proof of concept demonstrating the issue;

• screenshots or video evidence, where helpful;

• tools, scripts, or payloads used during testing;

• any scripts included as non-executable text where possible;

• the potential security impact;

• whether any sensitive information was accessed; and

• your contact details, unless you prefer to report anonymously.

Researchers may report anonymously. However, Uney may request additional information if needed to validate or remediate the issue.

By submitting a vulnerability report to Uney, you confirm that your submission does not knowingly infringe any third-party intellectual property rights and grant Uney a non-exclusive, royalty-free, worldwide license to use, reproduce, modify, and publish the report and related materials for vulnerability validation, remediation, security improvement, and coordinated disclosure purposes.


What you can expect from Uney

When you report a vulnerability to Uney in accordance with this policy, Uney will:

• acknowledge receipt of your report within three business days;

• review and evaluate the report as quickly as reasonably possible;

• handle your report with appropriate confidentiality;

• avoid requesting unnecessary additional testing after submission;

• where practical, inform you when the vulnerability has been remediated;

• where practical, allow you to verify that the reported vulnerability has been remediated;

• process any personal data you provide, such as your name and email address, in accordance with applicable data protection laws;

• not share your personal details with third parties without your permission, unless required by law;

• consider public acknowledgement of eligible researchers at Uney’s discretion and only with the researcher’s consent;

• credit duplicate reports based on the first sufficiently detailed valid submission; and

• for UAV-related reports, validate findings only in safe, simulated, non-production, or researcher-owned environments where appropriate.

Reports may be ineligible for recognition or further action if they are duplicated, previously known, out of scope, lack of security impact, lack sufficient validation detail, or violate this policy.


Disclosure

Uney is committed to the timely remediation of confirmed vulnerabilities.

Researchers must not publicly disclose a vulnerability or share vulnerability details with any third party until the vulnerability has been resolved or disclosure has been coordinated with Uney.

If you believe earlier disclosure is necessary, you must coordinate with the Uney Security Team in advance.

Uney may share vulnerability details with affected vendors, partners, customers, regulators, or service providers where necessary to investigate, remediate, or manage risk. Uney will not share researcher names or contact details without permission, unless required by law.


Questions

If you have questions about this policy, are unsure whether a specific test method is allowed, or are unsure whether a system is in scope, please contact:

[email protected]

Uney welcomes suggestions from the security community to help improve this policy.