Lumito is committed to the safety and security of the researchers, customers and organisations who use our products. We welcome good-faith reports of potential security vulnerabilities and operate a coordinated vulnerability disclosure (CVD) programme in line with the EU Cyber Resilience Act and the international standards ISO/IEC 29147 and ISO/IEC 30111.
On this page: How to report · What to include · What to expect · Good-faith research · Coordinated disclosure · Scope
Single point of contact — monitored by Lumito Product Security
Anyone — security researchers, customers, users, suppliers or authorities — can report a suspected vulnerability in a Lumito product. Reports are accepted in English or Swedish and are treated as confidential. Our contact channel is not limited to automated tools; you can always reach a person.
The machine-readable contact is published at /.well-known/security.txt (RFC 9116)
Please report privately first. Do not disclose a suspected vulnerability through public forums, support tickets or social media before coordinated disclosure has taken place (see below).
To help us assess and reproduce the issue quickly, please include as much of the following as you can:
Please avoid including sensitive personal data in screenshots or attachments, and make a good-faith effort not to access or destroy another user’s data.
We operate — not merely publish — this policy. The commitments below are what a reporter can expect, and they are recorded in our internal CVD register.
Stage | Our commitment | What we do |
|---|---|---|
Acknowledgement | Within 5 business days | We confirm we have received your report and give you a reference. |
Initial triage | Within 10 business days | We validate and, where possible, reproduce the issue, and give you an initial assessment (in scope / out of scope / more information needed). |
Status updates | At least every 30 days while open | We keep you informed of progress until the matter is resolved. |
Remediation | Risk-based, without undue delay | We develop and release a corrective or mitigating measure, prioritised by severity and exploitation status. |
Coordinated disclosure | After a fix or mitigation is available | We agree a disclosure date with you and publish an advisory once users have had a reasonable opportunity to protect themselves. |
We will not pursue or support legal action against anyone who reports a vulnerability in good faith and in accordance with this policy. We ask that you:
Testing that is destructive, that targets other users, or that involves extortion is not good-faith research and is not covered by this policy.
Lumito coordinates the timing and content of any public disclosure with the reporter. Our default is to publish a security advisory once a corrective or mitigating measure is available and users have had a reasonable opportunity to apply it. Where the security risk of publication outweighs the benefit, publication of specific details may be delayed until that risk has been reduced. Advisories credit the reporter unless anonymity is requested.
This policy applies to Lumito products with digital elements made available on the market, including the SCIZYS S1 scanner and any embedded, control or bundled software. Please note the following are outside the scope of this programme:
Coordinated vulnerability disclosure and regulatory reporting are separate but connected. This page governs Lumito’s relationship with the reporter. Where our assessment establishes reliable evidence that a vulnerability is being actively exploited, Lumito also notifies the relevant authorities (ENISA and the coordinator CSIRT) under the EU Cyber Resilience Act, and informs affected users — a process that runs in parallel with our work with you.