Crestwatch makes a connected river-level sensor and the service that carries its readings. If you have found a weakness in either, we would rather hear it from you than from an incident.
This inbox is monitored. Please do not report security issues through the public contact form, the ideas board, or social media — those are read by more people than need to see an unfixed vulnerability.
Last updated 2 August 2026
/api endpoints and the customer dashboard.Third-party services we build on (Supabase, Vercel, Stripe, Brevo, Zoho, Cloudflare) have their own disclosure programmes. If the flaw is in their platform rather than in how we use it, please report it to them — though we would still like to know.
Email security@crestwatchpro.com with:
Write in English or Italian. If you would like to encrypt your report, say so and we will send you a key.
| Stage | Our target |
|---|---|
| Acknowledge your report | Within 3 working days |
| Tell you our assessment and a rough timeline | Within 10 working days |
| Fix, or explain why we are not fixing it | Within 90 days for most issues |
| Tell you when it is fixed | As soon as the fix is live |
If a vulnerability is being actively exploited, we are separately obliged to notify ENISA and the relevant national CSIRT within 24 hours under the EU Cyber Resilience Act. That is a report about the flaw, not about you.
We will not pursue legal action, and will not ask anyone else to, against a person who reports a vulnerability in good faith under this policy — provided they act within it. If you are unsure whether something is in scope, ask first and we will tell you.
Crestwatch is a small company and does not currently run a paid bug-bounty programme. We will credit you by name on this page if you would like that, and we will always thank you properly.
The CWR-1C is supported with security updates for at least five years from the date the last unit of that revision is placed on the market. Firmware images are built reproducibly in CI, published with their SHA-256 digests, and each unit authenticates its reports with a per-device HMAC key that can be revoked.
Machine-readable version of this contact: /.well-known/security.txt (RFC 9116).
This page is about security flaws. If your concern is how Crestwatch handles your personal data, see the Privacy Policy or write to privacy@crestwatchpro.com. We will acknowledge a data-protection complaint within 3 working days and respond substantively within one month. You also have the right to complain to your national supervisory authority — in the UK that is the Information Commissioner's Office (ico.org.uk), and in Italy the Garante per la protezione dei dati personali (garanteprivacy.it).