Security Vulnerability Reporting Policy at Neat

Last updated September 20, 2026

This article defines Neat’s Security Vulnerability Reporting Policy. If you are considering reporting a security issue to us, please read this policy for guidance on scope, process, and what to expect.

We greatly value the time and effort researchers and customers put into identifying and responsibly reporting security vulnerabilities. Please note that Neat does not offer monetary rewards for vulnerability disclosures.

This policy is aligned with the principles of ISO/IEC 29147 (Vulnerability Disclosure) and ISO/IEC 30111 (Vulnerability Handling Processes).

Scope

In scope:

  • Neat hardware devices (Neat Bar, Neat Bar Gen 2, Neat Bar Pro, Neat Board, Neat Board Pro, Neat Board 50, Neat Board 32, Neat Pad, Neat Pad Pro, Neat Frame, Neat Center)
  • Neat Pulse (cloud management platform)

Out of scope:

  • Third-party platforms Neat integrates with (e.g., Zoom, Microsoft Teams, Google Meet), which should be reported to the respective vendors
  • Neat’s general corporate/marketing website, unless the issue has a direct security impact on customer data or product functionality
  • Denial-of-service testing, social engineering, physical security testing, or spam/volumetric testing against Neat infrastructure
  • Any testing that accesses, modifies, or discloses data belonging to another customer or user

Note: If you’re uncertain whether something is in scope, contact us at security@neat.no before testing further.

Good-Faith Research / Safe Harbor

Neat will not pursue legal action against researchers who:

  • Make a good-faith effort to comply with this policy;
  • Report vulnerabilities without exploiting them beyond what is necessary to demonstrate the issue;
  • Do not access, modify, exfiltrate, or destroy data belonging to Neat or its customers beyond what is necessary to prove the vulnerability; and
  • Do not disrupt Neat’s services or degrade the experience of other users.

If legal action is initiated by a third party related to research conducted in accordance with this policy, Neat will make this policy known to clarify that your actions were authorized.

How to Report a Security Issue

If you believe you have found a security vulnerability, please submit your report by emailing security@neat.no. You may also raise a support ticket by logging into your Neat Pulse portal, selecting your specific device, clicking the More icon, and choosing “Open support ticket”. Alternatively, you can submit a request through the post-sales contact form on the Neat Contact Page.

What Information Should You Include?

When reporting an issue, please include:

  • Name and/or model of the affected product or service;
  • Description of the vulnerability;
  • Potential impact;
  • Technical details for reproducing the vulnerability;
  • Proof-of-concept code, if applicable; and
  • Any other pertinent information.

What to Expect After You Report

  • We will acknowledge your report within 2 working days.
  • We aim to complete initial triage within 10 working days.
  • We will keep you informed of progress throughout our investigation, and you’re welcome to check in on status at any time. We may follow up for additional detail or clarification.
  • Remediation priority is assessed based on the impact, severity, and exploitation complexity of the issue.
  • We target resolution and coordinated public disclosure within 90 days of triage for most vulnerabilities. Complex issues requiring longer remediation timelines will be discussed and extended by mutual agreement with the reporter.
  • If you require an external statement from Neat before public disclosure, contact us and we’ll coordinate with you directly.
  • Where applicable, Neat will pursue CVE assignment for qualifying vulnerabilities.

Neat retains the right to modify the terms of this policy at any time.