关于我们 产品 技术博客 新闻中心 加入我们
商务合作 →
安全与合规

LIGHT ROBOTICS Security Vulnerability Disclosure Policy

本页目录

  1. 1. Scope
  2. 2. How to Report a Security Issue
  3. 3. What to Include in Your Report
  4. 4. Our Response Timeline
  5. 5. Coordinated Disclosure
  6. 6. Safe Harbor
  7. 7. Research Guidelines
  8. 8. Security Updates and Advisories

LIGHT ROBOTICS takes the security of our products and services seriously.

We encourage responsible security research and coordinated disclosure to help protect users and improve product security.

This policy is aligned with:

  • UK PSTI Act 2022
  • EU Cyber Resilience Act (CRA) expectations

1. Scope

This policy applies to all LIGHT ROBOTICS consumer products and services, including devices, software, cloud services, and interfaces.

2. How to Report a Security Issue

Please report suspected security vulnerabilities to:

Email: security@lightorigins.com
Web form: https://www.lightorigins.com/security-report-submit

You may submit a report without providing personal information. If you would like to receive acknowledgement and status updates, please provide a contact email address or another preferred contact method.

3. What to Include in Your Report

Please include as much of the following information as possible:

  • Product name, model and version affected
  • Firmware, software, mobile app or cloud component affected
  • Description of the vulnerability
  • Steps to reproduce
  • Proof-of-concept details, screenshots or logs
  • Potential impact
  • Whether you believe the vulnerability is being actively exploited
  • Any suggested remediation or mitigation

4. Our Response Timeline

We aim to:

  • Acknowledge within 3 business days
  • Provide initial assessment within 5 business days (where feasible)
  • Provide updates every 10 business days or agreed schedule

Critical vulnerabilities affecting user safety or active exploitation will be prioritized.

5. Coordinated Disclosure

We request researchers:

  • Do not publicly disclose vulnerabilities before remediation
  • Allow reasonable time for fixes and user protection
  • Coordinate disclosure timing with us in good faith

We aim to publish security advisories where appropriate.

6. Safe Harbor

We support responsible security research.

We will not initiate legal action against researchers who:

  • Act in good faith
  • Follow this policy
  • Avoid privacy violations
  • Avoid service disruption
  • Do not access or modify user data beyond what is necessary

Security testing performed under this policy is considered authorized activity.

7. Research Guidelines

When conducting security research, please:

  • Avoid accessing, modifying or deleting data that does not belong to you
  • Avoid actions that may interrupt, degrade or damage our products, services or users
  • Avoid social engineering, phishing, spam or physical attacks
  • Avoid denial-of-service testing unless explicitly authorised
  • Stop testing and notify us immediately if you encounter personal data, confidential information or evidence of compromise

8. Security Updates and Advisories

When a vulnerability is confirmed and remediated, we will provide security updates, mitigation guidance or a security advisory as appropriate. Security updates for supported products will be provided free of charge during the applicable security support period.

Information about the minimum security update support period for each product is available at: https://www.lightorigins.com/security-updates

我们仅在您同意后存储邮箱,用于发送产品与动态更新;可随时退订。详情见隐私政策。

Explore

关于我们 产品 技术博客 新闻中心

Company

加入我们 商务合作

Contact

business@lightorigins.com hr@lightorigins.com WeChat: LightOrigins

Locations

北京(中国) 深圳(中国) 新加坡
微信公众号二维码 抖音二维码
中 EN
© LIGHT ORIGINS 2026 · 亮源新创 · 保留所有权利
隐私政策 Cookie 政策 候选人隐私政策

Cookie 使用提示

我们目前仅使用分析类Cookie,用于统计访问人数、来源及页面浏览情况,以改进网站内容和性能。此类Cookie仅在获得您同意后才会设置。您可随时设置选择接受或拒绝,详情请参阅《Cookie政策》。