Vulnerability Disclosure Policy
iFIT Security Vulnerability Disclosure Policy
1. Purpose and Scope
This Security Vulnerability Disclosure Policy (the “Policy”) is designed to satisfy the reporting-of-security-issues requirements in Schedule 1, clause 3 of the Cyber Security (Security Standards for Smart Devices) Rules 2025, made under the Cyber Security Act 2024.
This Policy covers security issues affecting all connected fitness equipment supplied in Australia by iFIT Inc. (“iFIT”) (each, a “Product”), including: (a) the Product’s hardware; (b) software pre-installed on the Product when supplied to a consumer; (c) software that must be installed for all of iFIT’s intended purposes for the Product that use the Product’s hardware, pre-installed software or installable software; and (d) software developed by or on behalf of iFIT that is used for, or in connection with, any of iFIT’s intended purposes for the Product.
2. How to report a security issue
Security issues may be reported at any time, free of charge and without creating an account. Reporters are not required to provide personal information about themselves. Reporters may provide a return email address or other reasonable contact information so that iFIT can acknowledge the report and provide status updates. Reports should be submitted to: security@ifit.com
iFIT does not offer a bug bounty or monetary reward.
3. What to include in a report
To help us investigate quickly, please include where possible:
The affected product, model, or software/firmware version.
A description of the vulnerability and its potential impact.
Steps to reproduce the issue, including any proof-of-concept code, screenshots, or logs.
Whether the issue has been disclosed to any other party.
4. What happens after you report
Once a report is received, iFIT will respond according to the following response timeline:
EVENT | RESPONSE |
Acknowledgement of Receipt of a security report | Within 5 business days of receipt of the security report. |
Status Updates until resolution of the reported security concern. | Within 30 days of receipt of the security report, and every 30 days thereafter until the issue is resolved. |
5. Updates
iFIT may update this Policy from time to time. The version in effect when a security report is submitted will govern the handling of that report.
Questions about this Policy: Contact iFIT’s Legal Department at legal.department@ifit.com
