← All legal documentsLegal

Security & Vulnerability Disclosure Policy

Version 1.0 · Effective 1 January 2026

Documents
  • Terms of Use
  • Acceptable Use Policy
  • Community Guidelines
  • Privacy Policy
  • Cookie Policy
  • Data Retention Policy
  • AI Policy & Disclaimer
  • Intellectual Property Policy
  • Copyright & Trademark Notice
  • Waitlist Terms
  • Investor Disclaimer
  • Security & Vulnerability Disclosure Policy

Security & Vulnerability Disclosure Policy

Version: 1.0 · Effective Date: 1 January 2026

1. Introduction

LumoBond AB (under formation) ("LumoBond", "we", "us"), a company organised under the laws of Sweden, takes the security of our website, waitlist systems, and future platform and wearable seriously. We value the contributions of independent security researchers and members of the public who help us identify and address vulnerabilities. This Security & Vulnerability Disclosure Policy ("Policy") explains how to report a suspected security issue to us, what you can expect from us in response, and the safe harbour protections we offer to good-faith researchers.

2. Scope

This Policy applies to the website at lumobond.com, our waitlist infrastructure, our email communications systems, and any other digital assets we operate or control. As our platform and wearable are still in development, additional systems will be brought into scope as they are built and made available for testing, and we will update this Policy accordingly.

3. How to Report a Vulnerability

If you believe you have discovered a security vulnerability affecting our systems, please report it to us at support@lumobond.com. To help us investigate efficiently, please include, where possible:

  • A clear description of the vulnerability and its potential impact;
  • Step-by-step instructions to reproduce the issue, including any proof-of-concept code, screenshots, or video where relevant;
  • The URL, endpoint, or system affected;
  • The date and time you discovered or tested the issue;
  • Your contact information, so that we can follow up with questions or updates, and, if you wish, acknowledge your contribution.

We accept reports in English or Swedish.

4. What Happens Next

Once we receive your report, we will aim to:

  • Acknowledge receipt within five business days;
  • Provide an initial assessment of the report's validity and severity within fifteen business days, where reasonably possible;
  • Keep you informed of our progress towards resolution at reasonable intervals;
  • Notify you once the vulnerability has been remediated, where appropriate and where you have provided contact information.

Response times may vary depending on the complexity of the report and our available resources as an early-stage company, but we are committed to acting in good faith and with appropriate urgency, particularly for high-severity issues.

5. Safe Harbour

We consider security research conducted in accordance with this Policy to be authorised and conducted in good faith. Provided that you:

  • Make a good-faith effort to avoid privacy violations, degradation of service, and destruction or corruption of data;
  • Do not access, modify, or exfiltrate data belonging to other users or to LumoBond beyond what is strictly necessary to demonstrate the vulnerability;
  • Do not exploit a vulnerability beyond what is necessary to confirm its existence, for example by extracting more data than needed for a proof of concept;
  • Do not use social engineering, phishing, physical attacks, or denial-of-service techniques against our staff, users, or infrastructure;
  • Give us a reasonable opportunity to investigate and remediate the issue before disclosing it publicly, as described in section 6;
  • Comply with all applicable laws;

then we will not pursue or support legal action against you in relation to your research, and we will consider your conduct authorised for the purposes of applicable computer misuse and unauthorised access laws in Sweden and elsewhere, to the extent we have the ability to make such a determination. This safe harbour applies solely to conduct within the scope of, and consistent with, this Policy.

6. No Public Disclosure Before a Fix

We ask that you keep any information about a suspected or confirmed vulnerability strictly confidential and refrain from disclosing it publicly, to any third party, or on any forum, social media platform, or mailing list, until we have confirmed that the issue has been remediated or have otherwise agreed a disclosure timeline with you in writing. We aim to work with researchers towards coordinated disclosure and will not unreasonably delay remediation or agreement on a disclosure date. If you believe a vulnerability poses an imminent risk to users, please flag this urgency clearly in your report so that we can prioritise accordingly.

7. Out of Scope

The following activities and findings are generally considered out of scope for this Policy, unless you can demonstrate a credible, significant security impact: denial-of-service testing against production systems; spam or social engineering directed at our staff or waitlist members; automated vulnerability scanning that generates excessive traffic without prior coordination with us; reports based solely on missing security headers or cookie flags without a demonstrated exploitable impact; and vulnerabilities in third-party services or websites that we do not control, which should be reported directly to the relevant third party.

8. Recognition

Where you wish to be credited, and subject to our discretion and the sensitivity of the issue, we may acknowledge your contribution in a security acknowledgements page or communication once the vulnerability has been resolved. We do not currently operate a paid bug bounty programme, but we may consider discretionary recognition for significant, responsibly disclosed findings.

9. Legal Compliance

This Policy does not authorise any activity that would violate applicable law, including unauthorised access to systems or data outside the scope described above, or any activity affecting systems not owned or explicitly authorised by LumoBond.

10. Changes to This Policy

We may update this Security & Vulnerability Disclosure Policy from time to time as our systems, product scope, and processes evolve. The effective date above will be revised whenever changes are made.

11. Contact Us

To report a security concern, please contact support@lumobond.com. For general enquiries about this Policy, you may also use the same address.

LumoBond
Contacthello@lumobond.comInvestor Relationsinvestors@lumobond.comSUPPORTsupport@lumobond.com

LumoBond is currently in development. Product details, features and availability are subject to change without notice. Joining the waitlist does not constitute a purchase. Images are conceptual.

© 2026 LumoBond. All rights reserved.
Privacy PolicyTerms of UseWaitlist TermsCookie PolicyLegal Information