preloader

The security of our products is important to LyconSys. We continuously work to identify, assess and appropriately address potential security risks in our products.

If you discover a potential security vulnerability in a LyconSys product, we encourage you to report it to us responsibly. Security reports are reviewed and assessed according to their potential impact.

Reporting a Security Vulnerability

Please send reports of potential security vulnerabilities to:

security@lyconsys.com

This email address is intended exclusively for reports concerning potential security vulnerabilities and other security-related issues affecting our products.

For general technical support requests, please use our regular support contact channels.

What Information Should a Report Include?

To help us investigate a potential security vulnerability efficiently, please provide the following information where available:

  • affected LyconSys product,
  • firmware or software version,
  • description of the potential vulnerability,
  • steps required to reproduce the issue,
  • potential impact of the vulnerability,
  • relevant configuration information, if applicable,
  • logs, screenshots or a proof-of-concept, if applicable,
  • contact information for follow-up questions.

Please do not provide personal data, credentials or other confidential information unless it is necessary for investigating the reported issue.

Encrypted Communication

For the confidential transmission of security-related information, communication with LyconSys can be encrypted using OpenPGP.

Our public OpenPGP key for security reports is available at:

https://www.lyconsys.com/.well-known/security-pgp-key.txt

OpenPGP fingerprint:

991A 370F B0E9 9FFB 35A1 8432 9A34 73C6 ACCF 06D6

The associated OpenPGP key is used exclusively for communication related to IT security and security vulnerability reports.

Handling Security Reports

After receiving a security report, we review the information provided and assess whether and to what extent our products are affected.

Depending on the nature and severity of the vulnerability, appropriate measures may include providing a software or firmware update, an updated software package, a configuration change or a temporary workaround.

If additional information is required for our investigation, we may contact the reporter using the contact information provided.

Coordinated Disclosure

We ask security researchers, customers and other reporters to provide us with a reasonable opportunity to investigate and address a reported security vulnerability before publicly disclosing technical details of a vulnerability that has not yet been resolved.

This is intended in particular to prevent information about a vulnerability from being published before affected users have an opportunity to implement appropriate protective measures.

We aim to cooperate constructively and professionally with individuals who responsibly report security issues to us.

Security Advisories

Information about published security advisories, affected products and versions, as well as available updates or workarounds where applicable, is published in our support and documentation area.

Security Advisories

security.txt

LyconSys supports the standardized security.txt mechanism according to RFC 9116.

Our security.txt is available at:

https://www.lyconsys.com/.well-known/security.txt

Alliance for Cyber Security

LyconSys is a participant in the German Alliance for Cyber Security (Allianz für Cyber-Sicherheit, ACS), an initiative of the German Federal Office for Information Security (BSI).

Through our participation in the Alliance for Cyber Security, we use professional exchange and up-to-date information on cyber threats and security measures as an additional element of our continuous work on the security of our products and IT systems.

Participant in the Alliance for Cyber Security