Product Security – Invisible-Light Labs

Trust Center

Security

This page is the single point of contact for security matters concerning Invisible-Light Labs products. It explains how to report a vulnerability, what you can expect from us in return, and where to find our advisories, security updates, SBOMs and VEX statements.

Reporting a vulnerability

If you believe you have found a security vulnerability in an Invisible-Light Labs product, please tell us. We accept reports from anyone — customers, partners, independent security researchers and members of the public.

Email
security@invisible-light-labs.com
Encryption
OpenPGP key: pgp-key.txt
Fingerprint: [PGP FINGERPRINT]
Machine-readable
/.well-known/security.txt
Languages
German, English

No account and no registration are required. You may report anonymously; we will still process your report, although we will then be unable to send you status updates or credit you. If your report contains sensitive details, please encrypt it with our OpenPGP key.

What helps us most

  • The affected product, firmware or software version, and the specific component.
  • Reproduction steps, proof-of-concept or test evidence.
  • The impact you believe the issue has, and the preconditions an attacker needs.
  • How you would like to be credited in the advisory, or that you prefer not to be named.

Please do not publish exploitable details before we have coordinated a disclosure date with you.

What you can expect from us

Every report is registered, answered and closed in a traceable way — including reports that turn out to be outside our scope.

StepOur commitment
Acknowledgement of receiptWithin 3 business days
Validation resultWithin 10 business days, provided the report contains sufficient information
Status updatesAt least every 14 calendar days while the case is being worked on
PublicationWe inform you on the day of publication and whenever the planned date changes materially

User protection takes precedence over release, sales and reputational interests. We treat security researchers factually, respectfully and as partners.

Scope

This policy covers Invisible-Light Labs products with digital elements — [PRODUCT FAMILY NAME] — including their firmware, embedded operating system, device software, PC software, web interface and API, the third-party and open-source components shipped as part of the product, and the product-related build, signing and update chain.

In scope

  • Product firmware, the embedded Linux system and our own device software
  • PC client, backend, web frontend and the update function
  • USB, network, web, API, update and data-download interfaces
  • Third-party and open-source components that form part of the product

Out of scope

  • Corporate-IT incidents with no product relation
  • Customer-owned systems or extensions, as long as no product boundary is violated
  • Quality defects with no security relevance
  • Unrelated third-party products

If your finding falls outside this scope we will still acknowledge it, tell you so, and where possible point you to the right contact.

Safe harbour for security researchers

We will not pursue legal action against you for security research carried out in good faith under this policy, provided that you:

  • act only against your own devices, systems and data, or against systems you have explicit permission to test;
  • avoid privacy violations, service degradation, data destruction and any impact on third parties;
  • stop testing and report immediately as soon as you obtain access to data that is not yours;
  • give us reasonable time to remediate before disclosing publicly, in line with our disclosure policy below.

We credit reporters in our advisories where they consent to being named, and we will respect a request to remain anonymous.

Coordinated disclosure policy

  • We publish once a security update or an effective risk-mitigating measure is available.
  • We do not publish exploitable technical details while users have no effective remedy to apply.
  • An embargo agreed with a reporter never delays a legally required notification to the authorities.
  • Findings in third-party and open-source components are coordinated confidentially with the supplier or maintainer.
  • Where personal data is involved, we run the data-protection process in parallel.

Security advisories

Every advisory states the description of the vulnerability, the information needed to identify the affected products and versions, the impact and severity, the CVSS vector, the version in which it is fixed, any workaround, the advisory ID and a contact point.

No security advisories have been published to date. This section will list all advisories, newest first.

Because a substantial share of our devices is delivered through distribution partners, we notify users on several channels at once: this page, direct notification of known research institutes and industry partners, a support and distribution cascade where end users are not fully known to us, and a notice in the update download area and in the PC application where technically possible.

To be notified when we publish an advisory, write to security@invisible-light-labs.com.

Security updates

  • Security updates are provided without delay and free of charge, together with a notice telling you what action we recommend.
  • Where technically feasible we ship security updates separately from feature updates, so you can apply a security fix without also taking on functional changes.
  • Updates are distributed through a mechanism that protects their integrity — they are signed, and the signature is verified when the update is installed.
  • Where an update is not immediately possible, we publish a risk-mitigating measure instead: a configuration recommendation, disabling a service, network segmentation, or a recommendation to disconnect the device from the network.

Discontinued and end-of-life products

For discontinued products we first establish whether an update is technically possible at all. Where it is not, a permanent risk-mitigation recommendation takes the place of the update. Discontinued status does not change our obligation to handle the vulnerability.

Downloads: invisible-light-labs.com/security/updates · Support period per product: [SUPPORT PERIOD]

SBOM and VEX

We publish a software bill of materials for each product release. SBOMs are machine-readable in CycloneDX or SPDX format, archived per firmware and software release, and linked to the product, the version and the build ID. Each component entry carries its name, version, supplier or project, licence and a unique identifier.

VEX statements

An SBOM match does not mean a product is exploitable. Alongside the SBOM we publish VEX statements giving the actual affectedness of the product for a given vulnerability:

StatusMeaning
affectedThe product and version are affected; remediation is required.
not affectedThe match is not exploitable in this specific product. We always publish the technical justification.
under investigationAffectedness is still being analysed.
fixedThe vulnerability is remediated in a named version or by a named measure.
SBOM and VEX downloads per product release will be listed here.

If you maintain a component we ship and we find a vulnerability in it, we report it to you confidentially before any public disclosure.

Regulatory reporting

Where we become aware of an actively exploited vulnerability in one of our products, or of a severe security incident affecting the security of our products, we notify the competent authorities via the ENISA Single Reporting Platform within the statutory deadlines and inform affected users without undue delay.

A vulnerability that is known to us but is neither actively exploited nor tied to a severe incident is handled through our regular vulnerability management process and disclosed as described above.