π Security & Vulnerability Disclosure
Microfire makes sensor modules and supporting software. If you believe you have found a security vulnerability in any of our products, we want to hear from you and we will work with you to understand and resolve the issue.
Reporting a Vulnerability
Email: security@microfire.co
Please include as much of the following as you can:
- The product, module, or software involved (for example mod-EC, an Arduino library, or this website)
- The firmware, hardware, or library version, where applicable
- A description of the issue and its security impact
- Steps or code to reproduce the issue
We aim to acknowledge reports within 2 business days and will keep you informed of our progress toward a resolution. We ask that you give us a reasonable amount of time to address the issue before public disclosure or details are shared beyond our team. We are happy to coordinate on a joint publication and will credit researchers who request it.
Safe Harbor
We consider security research conducted in good faith and within the scope below to be authorized. We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
- Use only the techniques needed to demonstrate the vulnerability
- Stop testing and notify us as soon as an issue is demonstrated
- Do not exfiltrate data, establish persistent access, or use the issue to attack other targets
Scope
In scope:
- Microfire hardware modules (mod-EC, mod-pH, mod-ORP, mod-NTC, SHT30, 1-Wire interface modules) and their onboard firmware
- Our Arduino, Python, and ESPHome software libraries and components
- The microfire.co website and store
Out of scope:
- Social engineering, phishing, or physical attacks against us, our customers, or our infrastructure
- Denial-of-service, volumetric testing, or automated scanning of hosted services
- Vulnerabilities in third-party services or in dependency versions that we cannot patch upstream (do report these to the upstream project; we track them in our own dependency reviews)
- Self-reported issues in tools that output obvious error messages or intended behavior
How We Handle Reports
- Triage β We confirm we can reproduce or otherwise validate the report and determine which product versions are affected.
- Assessment β We evaluate the severity and real-world impact, including any effect on systems our modules are integrated into.
- Remediation β We develop a fix or mitigation. Depending on the product this may be a firmware or library update, updated integration guidance, reflash instructions, or replacement of affected hardware.
- Notification β We publish guidance for affected customers and coordinate disclosure with the original reporter. Where the EU Cyber Resilience Act requires it, we additionally notify the relevant authorities (see below).
EU Cyber Resilience Act (CRA)
Our modules are products with digital elements subject to Regulation (EU) 2024/2847. Since 11 September 2026, we monitor for actively exploited vulnerabilities and severe security incidents affecting our products and, where required by Article 14, report them through ENISAβs Single Reporting Platform (an early warning within 24 hours of awareness, a notification within 72 hours, and a final report to follow).
The CRAβs main product-security, CE marking, and technical documentation requirements apply to products placed on the EU market from 11 December 2027. Our modules are being prepared for conformity on that timeline. Integrators building our modules into their own products can find security and integration information in each moduleβs documentation, for example the mod-EC security and compliance section.
Security Support Period
We provide security support β vulnerability investigation, remediation guidance, and where applicable software or firmware updates β for each module version for at least five years from the date that version is placed on the market, consistent with CRA support-period requirements. If you need support beyond that period for a specific project, contact us.
Contact
- Security reports: security@microfire.co
- General contact: contact@microfire.co