Security and Vulnerability Reporting

Security is a core part of EVA Check-in. We welcome reports from customers, security researchers and others who believe they have identified a security vulnerability in EVA Check-in.

Report a security vulnerability

If you believe you have found a security vulnerability affecting EVA Check-in, please report it to:

security <at> theta.co.nz


Please include as much information as you can to help us understand and reproduce the issue, including:

  • The affected EVA Check-in service, application or component
  • A description of the vulnerability and its potential impact
  • Steps required to reproduce the issue
  • Relevant URLs, screenshots, logs or other supporting information
  • Any proof-of-concept code, where appropriate
  • Your preferred contact details for follow-up

Please do not include personal information, customer data or other sensitive information unless it is necessary to explain the vulnerability.

What you can expect from us

When you report a potential vulnerability, we will:

  • Acknowledge your report and assess the issue
  • Maintain communication with you where further information is required
  • Prioritise remediation based on the severity and potential impact of the vulnerability
  • Provide security updates or other mitigation measures where appropriate
  • Coordinate disclosure of confirmed vulnerabilities so customers have a reasonable opportunity to apply available fixes or mitigations before technical details are made public

We ask researchers to allow us reasonable time to investigate and address a reported vulnerability before publicly disclosing it.

Responsible security research

We support good-faith security research intended to improve the security of EVA Check-in. When investigating a potential vulnerability, please:

  • Avoid accessing, modifying, deleting or retaining data belonging to other users or organisations
  • Avoid actions that could disrupt EVA Check-in or our customers’ use of the service
  • Avoid denial-of-service testing, social engineering, phishing or physical security testing
  • Only access the minimum information necessary to demonstrate the vulnerability
  • Stop testing and contact us if you encounter personal, confidential or customer information
  • Do not use a vulnerability for purposes other than security research and reporting

Security advisories

When appropriate, we will publish information about confirmed and remediated security vulnerabilities affecting EVA Check-in. Security advisories may include:

  • A description of the vulnerability
  • Affected EVA Check-in products or versions
  • Severity and potential impact
  • Available security updates or mitigations
  • Actions customers should take
  • Relevant vulnerability identifiers, such as CVE identifiers, where applicable

In some circumstances, publication may be delayed where immediate disclosure could increase the security risk to EVA Check-in customers before appropriate protections are available.

Cyber Resilience Act

EVA Check-in maintains processes for vulnerability management and coordinated vulnerability disclosure consistent with the requirements of the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

This includes processes for receiving and assessing vulnerability reports, addressing identified vulnerabilities, distributing security updates or mitigations, communicating relevant security information to customers, and meeting applicable regulatory reporting requirements.

Contact

Manufacturer: Theta Systems Limited
Product: EVA Check-in
Security contact:
security <at> theta.co.nz
Postal address: 8-10 Beresford Square, Auckland 1010, New Zealand. 

For security vulnerabilities, please use the security contact above rather than general customer support.