vulnerability disclosure policy
teenage engineering ab
textilgatan 31
120 30 stockholm
sweden
+46 8 599 953 72
org nr 556718-3719
vat se 556718371901
all rights reserved
©2026 teenage engineering
textilgatan 31
120 30 stockholm
sweden
+46 8 599 953 72
org nr 556718-3719
vat se 556718371901
all rights reserved
©2026 teenage engineering
purpose
this policy provides a process for reporting identified security vulnerabilities affecting teenage engineering products, websites, online services and software.
scope
this policy covers security vulnerabilities affecting:
any services not expressly listed above and third-party products, services, and infrastructure that are not operated or controlled by teenage engineering are outside the scope of this policy.
reporting a vulnerability
if you have identified a security vulnerability, you may report to
security@teenage.engineering.
to help us assess a report, please include:
• the affected product, website, or service
• the relevant software or firmware version, where applicable
• a description of the vulnerability and its security impact
• sufficient information to reproduce or verify the issue
• any relevant proof of concept, logs, or other supporting information
handling of reports
we assess reported vulnerabilities and, where appropriate, coordinate remediation and disclosure.
reports consisting solely of automated scanner output, AI-generated analysis, vulnerability version matching, or reports without a demonstrated security impact may not receive an individual response.
disclosure timeline
we ask that reporters do not disclose details of a reported vulnerability to third parties or the public until a security update is available. we may disclose earlier if a vulnerability is being actively exploited. we may request an extension where a fix is technically complex or affects multiple products.
no bug bounty program
we do not operate a bug bounty program and do not offer compensation for vulnerability reports.
this policy provides a process for reporting identified security vulnerabilities affecting teenage engineering products, websites, online services and software.
scope
this policy covers security vulnerabilities affecting:
- teenage engineering products with digital elements
- websites operated by teenage engineering
- online services operated by teenage engineering
- software by teenage engineering
any services not expressly listed above and third-party products, services, and infrastructure that are not operated or controlled by teenage engineering are outside the scope of this policy.
reporting a vulnerability
if you have identified a security vulnerability, you may report to
security@teenage.engineering.
to help us assess a report, please include:
• the affected product, website, or service
• the relevant software or firmware version, where applicable
• a description of the vulnerability and its security impact
• sufficient information to reproduce or verify the issue
• any relevant proof of concept, logs, or other supporting information
handling of reports
we assess reported vulnerabilities and, where appropriate, coordinate remediation and disclosure.
reports consisting solely of automated scanner output, AI-generated analysis, vulnerability version matching, or reports without a demonstrated security impact may not receive an individual response.
disclosure timeline
we ask that reporters do not disclose details of a reported vulnerability to third parties or the public until a security update is available. we may disclose earlier if a vulnerability is being actively exploited. we may request an extension where a fix is technically complex or affects multiple products.
no bug bounty program
we do not operate a bug bounty program and do not offer compensation for vulnerability reports.