Security, support and data-access commitments for the hardware and software we supply — and how to reach us about a vulnerability.
Last updated: 21 September 2026
This page covers the products we supply — trackers, cameras, recorders and the fleet platform. It sets out how to report a vulnerability, how we handle security updates, what we publish about the AI in our products, and how to get the data your devices generate. Security of this website and the partner portal is covered separately in our Trust Center, which also carries our full position on the EU Cyber Resilience Act, AI Act and Data Act.
We do not claim compliance with those three regulations. Their main obligations apply between December 2026 and August 2028, and we are working towards them. Where an obligation already applies, this page says what we do today.
If you believe you have found a security vulnerability in one of our products, a device we have supplied, or our online services, we want to hear from you. We will not take legal action against researchers who follow this policy.
Email info@visiontelematics.com with “Security” in the subject line, or call 0800 020 9339 and ask for the security contact. Machine-readable details are published at /.well-known/security.txt. Please include enough detail for us to reproduce the issue: the product or URL affected, the steps involved, and what you were able to achieve.
Hardware and firmware we supply under our own part numbers; the fleet platform and partner portal; this website and its supporting services.
Findings that are not security issues — missing best-practice headers with no demonstrated impact, self-inflicted browser configurations, rate-limiting on unauthenticated public pages, and reports generated by automated scanners without a working proof of concept. Third-party services we merely link to are out of scope; please report those to their owners.
When we fix a vulnerability that affected a product in the field, we publish an advisory describing the issue, which products and versions were affected, how serious it was, and what you need to do. Advisories will be listed here.
No advisories have been published to date. That is a statement about the age of this process, not a claim that our products have never had a vulnerability.
Connected products need security updates for as long as they are in service. The EU Cyber Resilience Act requires manufacturers to declare a support period of at least five years — or the expected service life, where that is shorter — and to state its end date at the point of purchase.
We are currently establishing the support period for each product family with our manufacturing partners, and we will publish the end dates here and in product documentation as they are confirmed. If you need the position for a specific part number before then, ask us and we will tell you what we know.
Security updates are delivered remotely where the product supports it, and are always free of charge.
A software bill of materials lists the components a product is built from, which is what lets you work out quickly whether a newly published vulnerability affects you. We can provide an SBOM for products we supply, on request, to customers and to prospective customers under assessment. Email the address above with the part numbers you need.
The data your devices generate is yours. Under the EU Data Act, users of connected products have the right to access that data and to have it sent to a third party of their choosing.
Where personal data is involved — driver identities, for example — requests are handled alongside our obligations under UK GDPR. See the privacy policy.
Several of our products use AI. Being precise about what they do, and what they deliberately do not, matters both to the people in front of the camera and to the operators who answer for them.
What our AI does: detects collisions, lane departure and following distance; detects signs of fatigue and distraction, which are physical states, to warn the driver and prevent collisions; detects that people and vulnerable road users are present near a vehicle or machine; scores driving events such as harsh braking and cornering.
What our AI does not do: it does not attempt to infer emotions or mood; it does not perform facial recognition or biometric identification; it does not categorize people by any protected characteristic; and it does not make automated decisions about anyone’s employment. Inferring emotions in the workplace is a prohibited practice under the EU AI Act, and we hold our suppliers to that line as firmly as we hold ourselves.
Where driver-behavior scoring is used to monitor or evaluate employees, the operator is the employer and carries the corresponding duties — to be transparent with drivers, to keep a human in the decision, and to consult where required. We will support customers meeting those duties, and our fuller position is set out in the Trust Center.
Email info@visiontelematics.com or call 0800 020 9339. For anything security-related, please put “Security” in the subject line so it reaches the right people quickly.