lytra GmbH welcomes reports of security vulnerabilities in our products. This policy explains how to report one and what we commit to in return.
It is our policy on coordinated vulnerability disclosure under Annex I Part II(5) of Regulation (EU) 2024/2847 (Cyber Resilience Act).
Scope
In scope
- The lytra browser extensions for Google Chrome and Microsoft Edge
- The lytra add-in for Microsoft Outlook
- The lytra Data Client installed in customer environments
- Our web services:
app.lytra.ai,api.lytra.ai,auth.lytra.ai,extension.lytra.ai
Out of scope
- Staging, test and feature-branch environments (
*.staging.lytra.ai). They carry no production data, and findings there are not eligible. - Third-party services we use but do not operate
- Infrastructure operated by our customers, including their mail systems and databases
- Findings that require a compromised device, a malicious browser extension, or physical access to a signed-in machine
- Reports produced solely by an automated scanner, with no demonstrated impact
- Missing hardening headers, TLS configuration preferences, or rate-limiting observations with no demonstrated exploit path
How to report
Email security@lytra.ai, in German or English.
A useful report contains:
- The affected product or domain, and the version where you observed the vulnerability
- What the vulnerability allows an attacker to do, and under what preconditions
- Steps to reproduce it, ideally with a proof of concept
- Your assessment of severity, and any suggested remediation
Rules of engagement
Please keep to these rules when researching our products:
- Use your own test account. Do not access, modify, delete or exfiltrate data belonging to any other customer. If you come across third-party data by accident, stop, do not keep a copy, and tell us in your report.
- Do not degrade the service. No denial-of-service testing, no load or stress testing, and no automated scanning at a volume that affects other users.
- No social engineering of our staff, customers or suppliers, and no phishing.
- No physical attacks against our offices or staff.
- Report promptly, and give us a reasonable opportunity to fix the vulnerability before you disclose it to anyone else.
- Do not extort. A report made conditional on payment is not a security report, and we will treat it accordingly.
What we commit to
- Acknowledgement: within 3 business days of receipt
- Triage outcome: within 10 business days: accepted, rejected with reasons, or a request for more information
- Status updates: at least every 14 days while the report is open
- Remediation targets: critical within 7 days, high within 30 days, medium within 90 days, low with the next scheduled release
We will tell you when a fix ships. Where a vulnerability affects a released product, we publish a security advisory below. It describes the vulnerability, the affected versions, the impact and the remediation, as required by Annex I Part II(4) of the Cyber Resilience Act.
We aim to publish the advisory within 90 days of your report, or sooner if the fix is available earlier. Where publication would put users at disproportionate risk before they can realistically apply the update, we may delay it, and we will tell you why.
Unless you ask us not to, we credit reporters by name in the advisory.
No bug bounty
We do not currently run a paid bug bounty programme, and we do not pay for reports. We recognise contributions by crediting reporters in our advisories.
Escalation
If you have reported a vulnerability and received no response within 10 business days, write to info@lytra.ai.
Security advisories
No advisories have been published yet.