Security Policy
Maven Wireless Product Security & Vulnerability Disclosure
At Maven Wireless, the security, availability, and integrity of our products—including our off-air repeaters, Nebula DAS, and Maven NMS systems—are paramount. We welcome and encourage reports from security researchers, customers, and partners who identify potential security vulnerabilities.
How to Report a Vulnerability
If you believe you have discovered a security flaw or zero-day vulnerability in any Maven Wireless product or service, please notify our Incident Response Team immediately:
- Email Contact:
- Supported Languages: English
- Please Include:
- Product name and affected firmware/software versions.
- Technical description of the flaw and reproduction steps.
- Proof-of-Concept (PoC) logs or code snippets (if available).
- Your contact details and preferred credit/acknowledgment handle.
Important: Please do not submit confidential exploit details or zero-day proof-of-concept code via unencrypted web forms or third-party public tracking tools. Use direct communication to .
Our Response Commitments
When a vulnerability report is received, Maven Wireless commits to the following SLA guidelines:
- Initial Acknowledgment: Within 24 hours of receiving your email report.
- Triage & Validation: Within 48–72 hours to verify reproduction and assign an initial severity rating (using CVSS v4.0).
- Status Updates: Regular progress updates every 5 to 7 business days while a patch or mitigation is developed.
Coordinated Vulnerability Disclosure (CVD) & Safe Harbor
Maven Wireless adheres to the principle of Coordinated Vulnerability Disclosure (CVD) aligned with ISO/IEC 29147. We ask that reporters grant us a reasonable timeframe to analyze, patch, and verify fixes before publicly disclosing any technical details.
Safe Harbor Policy
Maven Wireless will not pursue legal action against security researchers who:
- Conduct research without causing service degradation, data destruction, or operational disruption to live customer environments.
- Refrain from accessing, exfiltrating, or modifying customer data.
- Maintain confidentiality and adhere to agreed disclosure embargo timelines.
- Comply with applicable local privacy laws.
Customer Security Advisories
Confirmed critical or high-severity vulnerabilities affecting customer environments will be addressed via targeted customer security notifications and published firmware update advisories in accordance with EU Cyber Resilience Act (CRA Article 14.8) obligations.