AutoStore

Vulnerability Disclosure Policy

Table of Contents

Last updated August 28, 2026

AutoStore is committed to the security of our products, our customers, and the warehouse operations they support. We recognise that collaboration with the security research community, customers, and users helps strengthen the security, resilience, and trustworthiness of our systems.

We welcome responsible reports of potential vulnerabilities affecting AutoStore-owned or AutoStore-controlled products.

AutoStore does not currently operate a bug bounty programme and does not offer financial rewards, gifts, or other compensation in exchange for vulnerability reports.

In-Scope Products

This policy applies only to products and systems that are:

  • Owned or provided by AutoStore; and/or
  • Directly managed by AutoStore,

unless otherwise stated.

How to Report a Vulnerability

Please report suspected vulnerabilities to:

Email: vulnerability@autostoresystem.com

Where possible, please include:

  • The type of vulnerability (e.g. authentication bypass, insecure API, remote code execution, injection, misconfiguration)
  • The affected product/system and version, if known
  • Step-by-step reproduction instructions
  • Proof-of-concept details, screenshots, or request/response examples
  • Potential impact, including any impact on physical warehouse operations
  • Suggested remediation, if you have one
  • Your contact details, if you'd like to be credited or kept informed

Please avoid including sensitive data in your report unless it's strictly necessary to demonstrate the issue. If your report involves suspected exposure of personal data, please flag this clearly so we can assess it under data protection law.

What to Expect After Reporting

We aim to:

  • Acknowledge receipt within a few business days
  • Validate whether the issue is reproducible and in scope
  • Assess severity and impact, and provide an initial response
  • Keep you informed of progress at reasonable intervals until resolution
  • Credit researchers who report in good faith, where they'd like to be credited (see Recognition below)

Duplicate reports may not receive individual recognition. Reports may be incorporated into our internal risk assessment and, where applicable, regulatory reporting processes.

Responsible Research Guidelines

Our products control physical robotic equipment, and unsafe testing can cause real-world harm, not just data or service disruption. Security research against AutoStore products must be conducted responsibly, lawfully, and with minimal impact to our systems, customers, and warehouse operations.

Researchers Should

  • Take only the steps necessary to demonstrate the vulnerability
  • Avoid accessing, modifying, exfiltrating, or retaining AutoStore, customer, or employee data beyond what's needed to demonstrate the issue
  • Immediately stop testing and notify us if you encounter personal data, operational data, credentials, or tokens
  • Securely delete any information inadvertently accessed
  • Use a sandbox or lab environment where one is offered, rather than live customer or warehouse systems
  • Avoid persistence, privilege escalation, or moving into other systems
  • Keep vulnerability details confidential until we've had reasonable time to remediate
  • Comply with all applicable laws

Strictly Prohibited Activities

  • Any testing against live, in-production warehouse robotics, operational technology (OT), or safety-critical control systems that could cause physical movement, damage, or injury
  • Denial-of-service, stress, load, or performance testing
  • Physical security testing of AutoStore or customer premises
  • Credential attacks, password spraying, brute force, session hijacking, or MFA bypass attempts
  • Social engineering, phishing, or impersonation of AutoStore or customer personnel
  • Malware deployment or other destructive or persistence-based testing
  • Testing third-party, supplier, or customer-operated systems without our written authorisation
  • Public disclosure before we've remediated the issue and given written approval

Any activity that could affect the physical safety of warehouse personnel, operational stability, or customer trust is prohibited, regardless of whether the underlying system is in scope.

Legal Position and Safe Harbour

AutoStore supports responsible security research conducted in good faith and in accordance with this policy. We will not initiate legal action against researchers for activity that:

  • Is conducted in good faith and complies with this policy
  • Avoids harm, disruption, or privacy violations, including to physical warehouse operations
  • Is promptly reported to us

We consider vulnerability research conducted consistently with this policy to be authorised. If a researcher unintentionally accesses limited sensitive information while acting in good faith, and reports it immediately without further access or disclosure, we won't treat this alone as malicious intent.

We reserve all rights in cases involving unlawful activity, intentional data exfiltration, extortion, threats, operational or physical disruption, unapproved public disclosure, testing of out-of-scope systems, or non-compliance with this policy.

You grant AutoStore a non-exclusive, royalty-free, unlimited, worldwide right to use the report and any associated materials (including code) for evaluating, remediating, and disclosing vulnerabilities.

Reports are submitted on an "as is" basis, and submitting a report doesn't obligate us to adopt any suggested fix. Norwegian law applies, with legal venue in Oslo, Norway.

Disclosure Timeline

We don't disclose vulnerability details publicly until a fix or mitigation is available. Where a fix takes longer than expected, we'll communicate progress and a revised timeline with the reporter. For actively exploited vulnerabilities or severe incidents, disclosure timing may also be coordinated with the relevant national cybersecurity authority.

Recognition

We appreciate responsible contributions from the security research community, customers, and users. While we don't currently offer financial rewards, we may, where appropriate:

  • Acknowledge researchers privately and/or publicly (please tell us if you'd prefer not to be)
  • Provide written recognition
  • Establish a responsible disclosure recognition programme in the future

This policy is reviewed annually or upon any material change to relevant regulatory guidance.