Product Security

Report a vulnerability

Lumito is committed to the safety and security of the researchers, customers and organisations who use our products. We welcome good-faith reports of potential security vulnerabilities and operate a coordinated vulnerability disclosure (CVD) programme in line with the EU Cyber Resilience Act and the international standards ISO/IEC 29147 and ISO/IEC 30111.

On this page: How to report · What to include · What to expect · Good-faith research · Coordinated disclosure · Scope

Single point of contact — monitored by Lumito Product Security

Anyone — security researchers, customers, users, suppliers or authorities — can report a suspected vulnerability in a Lumito product. Reports are accepted in English or Swedish and are treated as confidential. Our contact channel is not limited to automated tools; you can always reach a person.

The machine-readable contact is published at /.well-known/security.txt (RFC 9116)

Please report privately first. Do not disclose a suspected vulnerability through public forums, support tickets or social media before coordinated disclosure has taken place (see below).

What to include in a report​

To help us assess and reproduce the issue quickly, please include as much of the following as you can:

  • The affected product, model and software/firmware version.
  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, proof-of-concept or configuration details, where available.
  • Any evidence of active exploitation — this raises the report’s priority and may trigger regulatory reporting on our side.
  • How you wish to be credited, and your preferred contact details.

Please avoid including sensitive personal data in screenshots or attachments, and make a good-faith effort not to access or destroy another user’s data.

What to expect from us

We operate — not merely publish — this policy. The commitments below are what a reporter can expect, and they are recorded in our internal CVD register.

Stage
Our commitment
What we do
Acknowledgement
Within 5 business days
We confirm we have received your report and give you a reference.
Initial triage
Within 10 business days
We validate and, where possible, reproduce the issue, and give you an initial assessment (in scope / out of scope / more information needed).
Status updates
At least every 30 days while open
We keep you informed of progress until the matter is resolved.
Remediation
Risk-based, without undue delay
We develop and release a corrective or mitigating measure, prioritised by severity and exploitation status.
Coordinated disclosure
After a fix or mitigation is available
We agree a disclosure date with you and publish an advisory once users have had a reasonable opportunity to protect themselves.

Good-faith research (safe harbour)

We will not pursue or support legal action against anyone who reports a vulnerability in good faith and in accordance with this policy. We ask that you:

  • Make a good-faith effort to avoid privacy violations, data destruction, service disruption and degradation of our users’ experience.
  • Only interact with systems or accounts you own, or for which you have explicit permission.
  • Do not exfiltrate, retain or share any data you may encounter, and delete any such data once your report is made.
  • Give Lumito a reasonable opportunity to remediate before any public disclosure, and coordinate the disclosure date with us.

Testing that is destructive, that targets other users, or that involves extortion is not good-faith research and is not covered by this policy.

Coordinated disclosure and publication

Lumito coordinates the timing and content of any public disclosure with the reporter. Our default is to publish a security advisory once a corrective or mitigating measure is available and users have had a reasonable opportunity to apply it. Where the security risk of publication outweighs the benefit, publication of specific details may be delayed until that risk has been reduced. Advisories credit the reporter unless anonymity is requested.

Scope

This policy applies to Lumito products with digital elements made available on the market, including the SCIZYS S1 scanner and any embedded, control or bundled software. Please note the following are outside the scope of this programme:

  • Routine functional defects with no security impact.
  • Vulnerabilities in third-party systems or services not under Lumito’s control.
  • Reports generated solely by automated scanners without a demonstrated, exploitable impact.

How this relates to regulatory reporting

Coordinated vulnerability disclosure and regulatory reporting are separate but connected. This page governs Lumito’s relationship with the reporter. Where our assessment establishes reliable evidence that a vulnerability is being actively exploited, Lumito also notifies the relevant authorities (ENISA and the coordinator CSIRT) under the EU Cyber Resilience Act, and informs affected users — a process that runs in parallel with our work with you.