LIGHT ROBOTICS takes the security of our products and services seriously.
We encourage responsible security research and coordinated disclosure to help protect users and improve product security.
This policy is aligned with:
- UK PSTI Act 2022
- EU Cyber Resilience Act (CRA) expectations
1. Scope
This policy applies to all LIGHT ROBOTICS consumer products and services, including devices, software, cloud services, and interfaces.
2. How to Report a Security Issue
Please report suspected security vulnerabilities to:
Email: security@lightorigins.com
Web form: https://www.lightorigins.com/security-report-submit
You may submit a report without providing personal information. If you would like to receive acknowledgement and status updates, please provide a contact email address or another preferred contact method.
3. What to Include in Your Report
Please include as much of the following information as possible:
- Product name, model and version affected
- Firmware, software, mobile app or cloud component affected
- Description of the vulnerability
- Steps to reproduce
- Proof-of-concept details, screenshots or logs
- Potential impact
- Whether you believe the vulnerability is being actively exploited
- Any suggested remediation or mitigation
4. Our Response Timeline
We aim to:
- Acknowledge within 3 business days
- Provide initial assessment within 5 business days (where feasible)
- Provide updates every 10 business days or agreed schedule
Critical vulnerabilities affecting user safety or active exploitation will be prioritized.
5. Coordinated Disclosure
We request researchers:
- Do not publicly disclose vulnerabilities before remediation
- Allow reasonable time for fixes and user protection
- Coordinate disclosure timing with us in good faith
We aim to publish security advisories where appropriate.
6. Safe Harbor
We support responsible security research.
We will not initiate legal action against researchers who:
- Act in good faith
- Follow this policy
- Avoid privacy violations
- Avoid service disruption
- Do not access or modify user data beyond what is necessary
Security testing performed under this policy is considered authorized activity.
7. Research Guidelines
When conducting security research, please:
- Avoid accessing, modifying or deleting data that does not belong to you
- Avoid actions that may interrupt, degrade or damage our products, services or users
- Avoid social engineering, phishing, spam or physical attacks
- Avoid denial-of-service testing unless explicitly authorised
- Stop testing and notify us immediately if you encounter personal data, confidential information or evidence of compromise
8. Security Updates and Advisories
When a vulnerability is confirmed and remediated, we will provide security updates, mitigation guidance or a security advisory as appropriate. Security updates for supported products will be provided free of charge during the applicable security support period.
Information about the minimum security update support period for each product is available at: https://www.lightorigins.com/security-updates