Trust Centre
How Compass IoT identifies, assesses, prioritises, and remediates security vulnerabilities across our platform, infrastructure, and dependencies.
Last updated May 2026 · Compass IoT Pty Ltd
Our commitment
We actively look for weaknesses in our own systems.
This policy applies to all Compass IoT systems, infrastructure, platform code, third-party dependencies, and vendor relationships. It applies to all employees and contractors with a role in building, operating, or securing the platform.
Scope
This policy covers vulnerability identification and remediation across all layers of the Compass IoT environment:
Detection
Compass IoT uses a combination of automated scanning, manual testing, and external research to maintain continuous visibility over our vulnerability exposure.
Classification
All identified vulnerabilities are assigned a severity level using the Common Vulnerability Scoring System (CVSS) as a baseline, adjusted for context — including the exploitability of the specific vulnerability in our environment, the sensitivity of data at risk, and whether a fix is available.
Vulnerabilities that can be exploited remotely without authentication, or that provide direct access to customer data or administrative control of production systems. Requires immediate response.
Remediation target: within 48 hours of confirmed identification.
Vulnerabilities with significant exploitability or impact that require prompt action. May require authentication or specific conditions to exploit, but pose material risk if unaddressed.
Remediation target: within 7 days.
Vulnerabilities with limited exploitability or impact in isolation, but which should be addressed in the normal course of maintenance. May become higher severity in combination with other weaknesses.
Remediation target: within 30 days.
Minor weaknesses with negligible exploitability or impact. Tracked and addressed as part of scheduled maintenance cycles rather than requiring immediate action.
Remediation target: within 90 days.
Remediation
All confirmed vulnerabilities are tracked from identification through to remediation. No confirmed Critical or High vulnerability is left unresolved beyond its target remediation window without an explicit risk acceptance decision by the leadership team.
Step 01
Step 02
Step 03
Step 04
Risk acceptance
Where a vulnerability cannot be remediated within the target window — due to dependency on a third party, architectural constraints, or business impact of the fix — a formal risk acceptance decision is required from the leadership team. Accepted risks are documented, time-limited, and reviewed at the next scheduled review cycle. Risk acceptance is never a permanent resolution.
Penetration testing
Compass IoT conducts annual penetration tests carried out by an independent third-party. Penetration testing provides assurance that our controls are effective against realistic attack scenarios, not just known vulnerability patterns.
External reporting
Compass IoT operates a responsible disclosure programme for external researchers who discover potential vulnerabilities in our platform. We welcome good-faith security research and commit to responding transparently.
Policy review
This Vulnerability Management Policy is owned by Compass IoT's engineering leadership and reviewed annually, or following any incident where an unpatched or untracked vulnerability was a contributing factor.
Report a vulnerability
Security team
To report a suspected vulnerability, contact us directly.