Security is a core part of EVA Check-in. We welcome reports from customers, security researchers and others who believe they have identified a security vulnerability in EVA Check-in.
If you believe you have found a security vulnerability affecting EVA Check-in, please report it to:
Please include as much information as you can to help us understand and reproduce the issue, including:
Please do not include personal information, customer data or other sensitive information unless it is necessary to explain the vulnerability.
When you report a potential vulnerability, we will:
We ask researchers to allow us reasonable time to investigate and address a reported vulnerability before publicly disclosing it.
We support good-faith security research intended to improve the security of EVA Check-in. When investigating a potential vulnerability, please:
When appropriate, we will publish information about confirmed and remediated security vulnerabilities affecting EVA Check-in. Security advisories may include:
In some circumstances, publication may be delayed where immediate disclosure could increase the security risk to EVA Check-in customers before appropriate protections are available.
EVA Check-in maintains processes for vulnerability management and coordinated vulnerability disclosure consistent with the requirements of the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
This includes processes for receiving and assessing vulnerability reports, addressing identified vulnerabilities, distributing security updates or mitigations, communicating relevant security information to customers, and meeting applicable regulatory reporting requirements.
Manufacturer: Theta Systems Limited
Product: EVA Check-in
Security contact: security <at> theta.co.nz
Postal address: 8-10 Beresford Square, Auckland 1010, New Zealand.
For security vulnerabilities, please use the security contact above rather than general customer support.