Security
Vulnerability Disclosure Policy
At Iiwari, we take the security of our UWB positioning systems, Anchor devices, Tags, base stations and cloud infrastructure seriously. If you believe you have found a security vulnerability in our products or services, we encourage you to let us know right away. We will investigate all legitimate reports and do our best to quickly fix the problem.
Version 1.0, effective 22 September 2026
Scope
This policy covers all Iiwari products and services, including the Anchor, TileTag, BadgeTag and CloudTag devices, the MBS and BS base stations, and the Iiwari cloud services.
How to report a vulnerability
Please email your findings to security@iiwari.com. To help us triage and resolve the issue quickly, please include:
- A description of the vulnerability and its potential impact.
- The specific product, firmware version, or URL affected.
- A detailed description of the steps required to reproduce the vulnerability. Proof of concept scripts or screenshots are highly appreciated.
If your report contains sensitive details, you can encrypt it using our PGP key, available at https://iiwari.com/security/iiwari-security-public.asc. Its fingerprint is:
1264 3755 7209 02EC 54CF 0A66 C658 33BA 9B73 D1EA
You may send the encrypted report either as an attachment or in the body of the message. Both work.
What happens next
We will acknowledge receipt of your report within 3 business days, give you our initial assessment within 10 business days, and update you at least every 30 days until the issue is resolved.
Safe harbor
Iiwari supports safe harbor for security researchers. If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will not initiate legal action against you, and we will work with you to understand and resolve the issue quickly.
If a third party initiates legal action against you in relation to research carried out in accordance with this policy, we will make it known that your research was authorized.
This does not cover activity that breaks the law or harms our customers.
Guidelines for researchers
- Do not exploit a vulnerability further than necessary to establish its existence.
- Do not access, modify, or delete customer data.
- Do not perform denial of service attacks, and do not perform physical attacks against devices or infrastructure owned by Iiwari or our customers. Physical and hardware-level research on a device you own yourself is welcome.
- Keep the vulnerability details confidential until we have published them or agreed a disclosure date with you.
If you unintentionally access personal data or other sensitive information, please stop, tell us, and delete it.
Disclosure
We practice coordinated disclosure. We aim to publish information about a vulnerability once a fix or mitigation is available to users, and in any case no later than 90 days after your report. If we need more time, we will explain why and agree a new date with you. If a vulnerability is being actively exploited, we may publish earlier to protect users.
Some of our devices cannot be updated remotely. For these, a "fix" may mean a change in the surrounding system, deactivation of an affected device identifier, a corrected hardware revision, or a device replacement programme, and the timeline may be longer. We will tell you openly which applies to your report.
Recognition
We are happy to credit you by name when we publish, if you would like us to. We do not operate a bug bounty programme and are not able to offer monetary rewards.
Third-party components
If your finding concerns a third-party component used in our products, we will also report it to the component maintainer and coordinate disclosure with them.
Contact
Iiwari Tracking Solutions Oy
Kidekuja 2, 88610 Vuokatti, Finland
security@iiwari.com
https://iiwari.com
