Join our team - open positions available
lytra
Products
Automate technical supportAI-assisted troubleshooting for your machines
Identify & order spare partsFind the exact part and order it in one flow
IntegrationsConnect your ERP, CRM & service tools
ROI calculator About us Careers
EnglishDeutsch
Request a demo
EnglishDeutsch

Products

Automate technical support Identify & order spare parts Integrations

Company

ROI calculator About us Careers Contact
Request a demoContact us

Security

Vulnerability disclosure policy

Version 1.0, last updated 25 September 2026

lytra GmbH welcomes reports of security vulnerabilities in our products. This policy explains how to report one and what we commit to in return.

It is our policy on coordinated vulnerability disclosure under Annex I Part II(5) of Regulation (EU) 2024/2847 (Cyber Resilience Act).

Scope

In scope

  • The lytra browser extensions for Google Chrome and Microsoft Edge
  • The lytra add-in for Microsoft Outlook
  • The lytra Data Client installed in customer environments
  • Our web services: app.lytra.ai, api.lytra.ai, auth.lytra.ai, extension.lytra.ai

Out of scope

  • Staging, test and feature-branch environments (*.staging.lytra.ai). They carry no production data, and findings there are not eligible.
  • Third-party services we use but do not operate
  • Infrastructure operated by our customers, including their mail systems and databases
  • Findings that require a compromised device, a malicious browser extension, or physical access to a signed-in machine
  • Reports produced solely by an automated scanner, with no demonstrated impact
  • Missing hardening headers, TLS configuration preferences, or rate-limiting observations with no demonstrated exploit path

How to report

Email security@lytra.ai, in German or English.

A useful report contains:

  • The affected product or domain, and the version where you observed the vulnerability
  • What the vulnerability allows an attacker to do, and under what preconditions
  • Steps to reproduce it, ideally with a proof of concept
  • Your assessment of severity, and any suggested remediation

Rules of engagement

Please keep to these rules when researching our products:

  • Use your own test account. Do not access, modify, delete or exfiltrate data belonging to any other customer. If you come across third-party data by accident, stop, do not keep a copy, and tell us in your report.
  • Do not degrade the service. No denial-of-service testing, no load or stress testing, and no automated scanning at a volume that affects other users.
  • No social engineering of our staff, customers or suppliers, and no phishing.
  • No physical attacks against our offices or staff.
  • Report promptly, and give us a reasonable opportunity to fix the vulnerability before you disclose it to anyone else.
  • Do not extort. A report made conditional on payment is not a security report, and we will treat it accordingly.

What we commit to

  • Acknowledgement: within 3 business days of receipt
  • Triage outcome: within 10 business days: accepted, rejected with reasons, or a request for more information
  • Status updates: at least every 14 days while the report is open
  • Remediation targets: critical within 7 days, high within 30 days, medium within 90 days, low with the next scheduled release

We will tell you when a fix ships. Where a vulnerability affects a released product, we publish a security advisory below. It describes the vulnerability, the affected versions, the impact and the remediation, as required by Annex I Part II(4) of the Cyber Resilience Act.

We aim to publish the advisory within 90 days of your report, or sooner if the fix is available earlier. Where publication would put users at disproportionate risk before they can realistically apply the update, we may delay it, and we will tell you why.

Unless you ask us not to, we credit reporters by name in the advisory.

No bug bounty

We do not currently run a paid bug bounty programme, and we do not pay for reports. We recognise contributions by crediting reporters in our advisories.

Escalation

If you have reported a vulnerability and received no response within 10 business days, write to info@lytra.ai.

Security advisories

No advisories have been published yet.

lytra

lytra - the AI operating system for manufacturing service.

Request a demo
info@lytra.aiLinkedIn

Product

  • Automate technical support
  • Identify & order spare parts
  • Integrations
  • ROI calculator

Company

  • About us
  • Careers

Legal

  • Privacy policy
  • Legal notice
  • Security
© 2026 lytra. All rights reserved.Made in Germany, Munich