Smart Pet Product App, Firmware and Cloud Checklist
A connected device is not only hardware. Buyers also need to understand who controls the app listing, user accounts, firmware, cloud service, security support and end-of-service process. This checklist asks for written evidence; it does not claim that every field is available for every NAVORIQ model.
1. Lock the hardware, firmware and app combination
Record the exact hardware model and revision, current firmware version, app name and version, supported operating systems, connection method and destination region. Do not assume two products with the same enclosure use the same app or cloud configuration.
2. Identify who owns and publishes the app
Request the live app-store links, publisher legal name, developer-account owner, support contact and branding rights. For a private-label project, ask whether the buyer receives its own listing, a branded tenant, a shared supplier app or another arrangement—and who can approve future releases.
- App Store and Google Play links
- Publisher and developer-account owner
- Trademark and listing-control rights
- Release and review responsibility
- Support contact and escalation path
3. Map accounts, permissions and data
Ask what information is collected from the device and user, whether camera or audio data is involved, where data is processed or stored, who acts as the relevant data controller or processor, how long data is retained and how a user can export or delete it. Request the current privacy notice for the exact app and region.
4. Confirm firmware and security support
Request the update mechanism, authorization method, version history, rollback or recovery process, support period and vulnerability-reporting contact. NIST's current IoT guidance treats software updates, documentation and lifecycle support as buyer-relevant capabilities; the exact requirement still depends on the product and market.
5. Plan for cloud interruption and end of service
Document what the device can do without internet access, what happens during a cloud outage, how users can unbind or factory-reset the device, and what migration or notice process applies if the platform, app publisher or service ends. Put the responsible party and notice period into the commercial agreement.
6. Test the agreed digital journey on the sample
Use a destination-appropriate phone and account to record installation, account creation, pairing, permissions, key controls, notifications, offline behavior, update behavior, unbinding and deletion. Save app versions, screenshots and evidence IDs with the approved sample record.
Written evidence request for connected pet products
The buyer should request the same fields for every shortlisted model. 'Not yet confirmed' is safer than filling a gap with a claim from a different product.
| Due-diligence field | Supplier provides in writing | Buyer checks on the sample |
|---|---|---|
| Exact digital configuration | Hardware revision, firmware, app version, radio method and supported region/OS. | The sample matches the named combination and can be identified later. |
| App publication and ownership | Store links, publisher, developer-account owner, branding model and release responsibility. | The links are live in the target region and show the stated publisher. |
| Accounts and access | Registration fields, roles, sharing, password/reset process and account deletion. | Create, share, recover, unbind and delete a test account as agreed. |
| Data and privacy | Collected data, camera/audio scope, purposes, retention, deletion, service providers and processing regions. | Permissions and in-app notices match the supplied privacy documentation. |
| Firmware and support | Update method, authorization, release history, support period, vulnerability contact and end-of-life notice. | Record the version and test the agreed update or recovery path where practical. |
| Cloud continuity | Offline behavior, outage responsibility, backup/migration, factory reset and service-end plan. | Record what remains usable with the internet unavailable and after re-pairing. |
| Private-label control | Rights to brand, publish, receive source/build assets or transfer service—only where contractually offered. | Approved branding and account ownership match the written commercial scope. |
The current NAVORIQ source records do not establish app-store ownership, server region, privacy role, firmware support period or transfer rights for all models. Request those answers for the exact version before quotation approval.
Sources and review basis
External pages were last reviewed on 2026-08-31. Their content may change; use the linked source for the current version. NAVORIQ model facts are based on the supplied product documents, not copied from external examples.
- NIST IR 8259 Rev. 1 Current foundational cybersecurity activities for IoT product manufacturers across pre-market and post-market support.
- NIST IoT manufacturer documentation catalog Buyer-relevant documentation prompts for interfaces, data sharing, software maintenance, cloud services and lifecycle support.
- GOV.UK: Consumer connectable product security Official UK guidance on product-security duties that may apply to relevant consumer connectable products.
- European Commission: Cyber Resilience Act Official EU overview of lifecycle cybersecurity and software-update expectations for products with digital elements.