Vulnerability Disclosure Policy
Help Us Secure the Physical World
At LVT, the security of our systems and the safety of our customers’ data are our top priorities. We value the work of the security research community and believe that a robust, collaborative disclosure process is vital to maintaining a secure ecosystem.
To ensure all disclosures are handled with the highest level of care and rewards, we have transitioned our vulnerability reporting to a private bug bounty program hosted by Bugcrowd.
How to Report a Vulnerability
LVT currently operates a private invite-only program. If you have discovered a potential security vulnerability in an LVT product or service, please follow these steps to receive an invite to our Bugcrowd program:
- Bugcrowd Account: Ensure you have an active researcher account at Bugcrowd.com.
- Request an Invite: Email us at security@lvt.com.
- Include Details: In your email, please provide the email address associated with your Bugcrowd account.
- Verification: Our security team will review your request and issue an invitation to the LVT private program, where you can submit your findings, view our full scope, and track your submission.
Our Commitment
While the specific scope and reward structures are managed within the Bugcrowd platform, LVT remains committed to:
- Timely Response: We will acknowledge receipt of your invite request and findings promptly.
- Collaboration: We will work with you to understand and validate your report.
- Safe Harbor: LVT will not take legal action against researchers who submit reports in good faith and adhere to the guidelines set forth in our Bugcrowd program.
Safe Harbor Guidelines
When conducting security research, we ask that you:
- Avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data.
- Only perform research within the scope defined in the Bugcrowd program.
- Provide LVT a reasonable amount of time to resolve the issue before any public disclosure.
Interested in joining our mission? Email security@lvt.com to request an invite.