
The Kavalan Device Diligence Checklist
- What is the intended purpose of the device in your home?
- Who is the device maker?
- Have there been prior cyber breaches at this vendor?
- If there was a breach in the past,
- how did the device maker respond to the breach?
- did the device maker notify customers about the breach in a timely manner?
- how did they compensate or protect customers impacted by the breach?
- How often does the device maker issue patches/updates?
- What sensors and extensions does the device need in order to function?
- Camera, microphone, Bluetooth, network, storage, social media, contact list, etc?
- Always needed or can access be limited to only in use?
- Full access or ‘as needed’ access?
- What functionality do you lose if you do not provide access to different sensors?
- What information does the device collect?
- Does the device NEED all of the information collected in order to function?
- Does the device allow apps to collect information?
- Does the device require subscription to a cloud service in order for it to function?
- If so, does the device encrypt network traffic to the cloud service?
- Does the device require the install of a remote administration app to manage or access the device from outside the home? If so then:
- What security protection is included in the app? Passwords? Two-factor?
- Does the device use a non-standard network port to communicate with its app?
- Does the device encrypt network traffic to the app?
- Does the device maker have a privacy policy?
- Are the terms of service and the privacy policy consistent with each other i.e. no conflicting language?
- Does the device maker update customers when there are changes to the privacy policy?
- What are the privacy settings internal to the device?
- Do privacy settings change or reset to factory settings after updates?
- What does the device or vendor do with the information collected?
- Does the device maker share information with third parties?
- Does the device NEED to share information with third parties in order to function?
- Does the device sell information to third parties?
- Does the device expose my information to advertisers? If so :
- Which companies does it share with?
- Does it allow me to opt out of sharing with advertisers?
- What rights does the device maker allow me to enforce on the privacy policy?
- Do not collect
- Do not share
- Do not sell
- Request data record
- Delete my data
- What is the expected lifetime of the device and will the device maker issue patches/updates for that lifetime?
- What happens to your data when the device maker announces planned obsolescence?
- Is there a way to backup and/or wipe all the data from the device before disposing it?
- Will the device still function if the device maker does not exist any more?
- Do privacy settings change or reset to factory settings after software or firmware updates?
- Does the device need to be running on the home network all the time?
- Does the device need to talk to other devices on the network in order to function?
Disclaimer: This information is being shared purely as a free reference . The information provided may not be accurate or up to date. Please make sure to review the device maker as well as the device vendor's terms of service and privacy policy. Use at your own risk.