train tunnel

Security Policy

Maven Wireless Product Security & Vulnerability Disclosure

At Maven Wireless, the security, availability, and integrity of our products—including our off-air repeaters, Nebula DAS, and Maven NMS systems—are paramount. We welcome and encourage reports from security researchers, customers, and partners who identify potential security vulnerabilities.

How to Report a Vulnerability

If you believe you have discovered a security flaw or zero-day vulnerability in any Maven Wireless product or service, please notify our Incident Response Team immediately:

  • Email Contact:
  • Supported Languages: English
  • Please Include:
    • Product name and affected firmware/software versions.
    • Technical description of the flaw and reproduction steps.
    • Proof-of-Concept (PoC) logs or code snippets (if available).
    • Your contact details and preferred credit/acknowledgment handle.

Important: Please do not submit confidential exploit details or zero-day proof-of-concept code via unencrypted web forms or third-party public tracking tools. Use direct communication to .

Our Response Commitments

When a vulnerability report is received, Maven Wireless commits to the following SLA guidelines:

  • Initial Acknowledgment: Within 24 hours of receiving your email report.
  • Triage & Validation: Within 48–72 hours to verify reproduction and assign an initial severity rating (using CVSS v4.0).
  • Status Updates: Regular progress updates every 5 to 7 business days while a patch or mitigation is developed.

Coordinated Vulnerability Disclosure (CVD) & Safe Harbor

Maven Wireless adheres to the principle of Coordinated Vulnerability Disclosure (CVD) aligned with ISO/IEC 29147. We ask that reporters grant us a reasonable timeframe to analyze, patch, and verify fixes before publicly disclosing any technical details.

Safe Harbor Policy

Maven Wireless will not pursue legal action against security researchers who:

  • Conduct research without causing service degradation, data destruction, or operational disruption to live customer environments.
  • Refrain from accessing, exfiltrating, or modifying customer data.
  • Maintain confidentiality and adhere to agreed disclosure embargo timelines.
  • Comply with applicable local privacy laws.

Customer Security Advisories

Confirmed critical or high-severity vulnerabilities affecting customer environments will be addressed via targeted customer security notifications and published firmware update advisories in accordance with EU Cyber Resilience Act (CRA Article 14.8) obligations.