Home / Product Compliance

Product Compliance

Security, support and data-access commitments for the hardware and software we supply — and how to reach us about a vulnerability.

Last updated: 21 September 2026

What this page is

This page covers the products we supply — trackers, cameras, recorders and the fleet platform. It sets out how to report a vulnerability, how we handle security updates, what we publish about the AI in our products, and how to get the data your devices generate. Security of this website and the partner portal is covered separately in our Trust Center, which also carries our full position on the EU Cyber Resilience Act, AI Act and Data Act.

We do not claim compliance with those three regulations. Their main obligations apply between December 2026 and August 2028, and we are working towards them. Where an obligation already applies, this page says what we do today.

Coordinated vulnerability disclosure

If you believe you have found a security vulnerability in one of our products, a device we have supplied, or our online services, we want to hear from you. We will not take legal action against researchers who follow this policy.

How to report

Email info@visiontelematics.com with “Security” in the subject line, or call 0800 020 9339 and ask for the security contact. Machine-readable details are published at /.well-known/security.txt. Please include enough detail for us to reproduce the issue: the product or URL affected, the steps involved, and what you were able to achieve.

What we commit to

  • We acknowledge every report within three working days.
  • We give you an initial assessment, including whether we consider it a vulnerability, within ten working days.
  • We keep you informed while we work on a fix, and we tell you when it ships.
  • We credit you when we publish an advisory, unless you would rather we did not.
  • We do not charge for security updates, and we never will.

What we ask of you

  • Give us a reasonable opportunity to fix the issue before you disclose it publicly.
  • Do not access, modify or delete anyone else’s data, and stop as soon as you have enough to demonstrate the problem.
  • Do not degrade service for other users — no denial-of-service testing, no spam, no social engineering of our staff or customers.
  • Do not test physical security or attempt to access a customer’s vehicle or site.

In scope

Hardware and firmware we supply under our own part numbers; the fleet platform and partner portal; this website and its supporting services.

Out of scope

Findings that are not security issues — missing best-practice headers with no demonstrated impact, self-inflicted browser configurations, rate-limiting on unauthenticated public pages, and reports generated by automated scanners without a working proof of concept. Third-party services we merely link to are out of scope; please report those to their owners.

Security advisories

When we fix a vulnerability that affected a product in the field, we publish an advisory describing the issue, which products and versions were affected, how serious it was, and what you need to do. Advisories will be listed here.

No advisories have been published to date. That is a statement about the age of this process, not a claim that our products have never had a vulnerability.

Security updates and support periods

Connected products need security updates for as long as they are in service. The EU Cyber Resilience Act requires manufacturers to declare a support period of at least five years — or the expected service life, where that is shorter — and to state its end date at the point of purchase.

We are currently establishing the support period for each product family with our manufacturing partners, and we will publish the end dates here and in product documentation as they are confirmed. If you need the position for a specific part number before then, ask us and we will tell you what we know.

Security updates are delivered remotely where the product supports it, and are always free of charge.

Software bill of materials

A software bill of materials lists the components a product is built from, which is what lets you work out quickly whether a newly published vulnerability affects you. We can provide an SBOM for products we supply, on request, to customers and to prospective customers under assessment. Email the address above with the part numbers you need.

Your data — access and portability

The data your devices generate is yours. Under the EU Data Act, users of connected products have the right to access that data and to have it sent to a third party of their choosing.

  • To get your data: ask us, or your account manager, and tell us the period and the vehicles or assets involved. We provide it in a structured, machine-readable format, free of charge.
  • To send it somewhere else: tell us who to send it to and we will, on your instruction. That includes another supplier.
  • What we will not do: we do not use the data your products generate to compete with you.

Where personal data is involved — driver identities, for example — requests are handled alongside our obligations under UK GDPR. See the privacy policy.

AI in our products

Several of our products use AI. Being precise about what they do, and what they deliberately do not, matters both to the people in front of the camera and to the operators who answer for them.

What our AI does: detects collisions, lane departure and following distance; detects signs of fatigue and distraction, which are physical states, to warn the driver and prevent collisions; detects that people and vulnerable road users are present near a vehicle or machine; scores driving events such as harsh braking and cornering.

What our AI does not do: it does not attempt to infer emotions or mood; it does not perform facial recognition or biometric identification; it does not categorize people by any protected characteristic; and it does not make automated decisions about anyone’s employment. Inferring emotions in the workplace is a prohibited practice under the EU AI Act, and we hold our suppliers to that line as firmly as we hold ourselves.

Where driver-behavior scoring is used to monitor or evaluate employees, the operator is the employer and carries the corresponding duties — to be transparent with drivers, to keep a human in the decision, and to consult where required. We will support customers meeting those duties, and our fuller position is set out in the Trust Center.

Questions

Email info@visiontelematics.com or call 0800 020 9339. For anything security-related, please put “Security” in the subject line so it reaches the right people quickly.