Coordinated Vulnerabilities Disclosure Policy

Manufacturer: Luna Innovations

Policy owner: Product Security Incident Response Team — PSIRT

Created / last modified: 2026-08-24

Next scheduled review: 2027-10-01 Version: 1.0

Luna Innovations is committed to maintaining the security of our products, services, and systems. If you believe you have identified a potential security vulnerability, please report it to us promptly. Your responsible disclosure gives our team an opportunity to investigate the issue and take appropriate corrective action.

We appreciate the contributions of security researchers who help us strengthen the security of Luna products and systems through responsible disclosure. Luna does not currently offer financial compensation, bounties, or other rewards for vulnerability reports. All reports are submitted voluntarily and support our ongoing efforts to improve security.

 

  • Scope

    This policy covers vulnerability reports affecting: 

    • Luna products with digital elements; 
    • Luna software, firmware, embedded systems, applications, cloud services, and APIs; 
    • Luna-maintained product documentation where security-relevant misconfiguration or misuse could result; 
    • Luna infrastructure, websites, portals, and support systems; 
    • third-party components used in Luna products where Luna can coordinate remediation or mitigation.
  • Vulnerability Reporting Channels

    Please report suspected vulnerabilities using one of the following channels.

    Product vulnerabilities — PSIRT

    Use this channel for vulnerabilities affecting Luna products, software, firmware, embedded devices, product services, or product-related cloud components. 

    Infrastructure vulnerabilities — CSIRT

    Use this channel for vulnerabilities affecting Luna websites, corporate infrastructure, portals, or other Luna-operated IT systems. 

    Web form for vulnerability reports

    Reports may also be submitted via the vulnerability reporting web form. Please see the form at the bottom of this page.

  • Secure Communication

    Luna recommends that reporting entities use encrypted and digitally signed email when transmitting confidential vulnerability information, proof-of-concept material, exploit details, logs, or any other sensitive information.

    OpenPGP keys for Luna’s PSIRT and CSIRT are available at the direct download locations listed above. Luna will publish and maintain the corresponding fingerprints together with the keys. 

  • Information to Include in a Vulnerability Report

    To help Luna validate and assess a vulnerability efficiently, please include as much of the following information as possible:

    • affected product, service, software, firmware, device, version, build, or configuration; 
    • description of the suspected vulnerability;
    • steps to reproduce the issue;
    • proof-of-concept or technical evidence, where safe and appropriate;
    • potential security impact;
    • whether the vulnerability is known to be actively exploited;
    • any known mitigations or workarounds;
    • your preferred contact method;
    • whether you wish to be acknowledged publicly after completion of the CVD process. 
  • Luna’s Assurances to Reporting Entities

    Luna will: 

    1. treat incoming vulnerability reports confidentially to the maximum extent permitted by applicable law, except for information required for public vulnerability disclosure;
    2. not disclose personal data of the reporting entity to third parties without explicit consent, unless legally required;
    3. provide responses within the response times stated in this policy;
    4. act as a trusted contact throughout the CVD process;
    5. not require the reporting entity to sign a non-disclosure agreement — NDA — as a condition for reporting or coordination;
    6. not intend to pursue legal action against a reporting entity acting in good faith and in accordance with this policy, subject to applicable law and contractual obligations. This does not apply if recognizable criminal intentions have been or are being pursued.
    7. recommend the use of encrypted and digitally signed email for confidential information;
    8. consider public acknowledgement, if requested by the reporting entity, after a valid vulnerability has been reported and the CVD process has been completed. 
  • Code of Conduct for Reporting Entities

    To support safe and responsible vulnerability handling, Luna asks reporting entities to: 

    • act in good faith;
    • avoid causing damage beyond what is necessary to demonstrate the vulnerability;
    • avoid accessing, modifying, deleting, exfiltrating, or compromising data that does not belong to them;
    • avoid privacy violations and unnecessary exposure of personal data;
    • avoid social engineering, phishing, spam, brute-force attacks, denial-of-service attacks, or distributed denial-of-service attacks;
    • avoid disrupting Luna systems, services, customers, or third parties;
    • avoid offering exploit tools or exploit services to third parties for misuse;
    • communicate respectfully with all involved parties;
    • allow Luna reasonable time to investigate, mitigate, remediate, and coordinate disclosure.

    Failure to follow this code of conduct may affect eligibility for acknowledgement. However, Luna will still assess submitted vulnerability information to the best extent possible.

  • Response Times

    For non-anonymous vulnerability reports, Luna will provide:

    • Initial human response: within five working days of receiving the report or an update to an existing report;
    • Detailed feedback: within ten working days after further analysis.

    The detailed feedback will include at least one of the following:

    • confirmation or rejection of the reported vulnerability;
    • meaningful follow-up questions needed to understand or reproduce the vulnerability;
    • an explanation why the investigation is taking longer, together with a commitment to provide a further update within ten working days.
  • Handling of Actively Exploited Vulnerabilities

    If Luna becomes aware of an actively exploited vulnerability affecting a Luna product, service, or infrastructure, Luna will notify its corresponding national CSIRT without undue delay.

    Luna will also inform the corresponding national CSIRT about relevant new information, mitigation measures, remediation plans, and schedules, and will coordinate these where required.

    For Luna entities established in Germany, the corresponding national CSIRT is expected to be CERT-Bund / BSI, unless another competent CSIRT is applicable based on the legal establishment and product context.

  • Vulnerability Validation and Assessment

    After receiving a report, Luna will:

    1. acknowledge receipt, where contact information is available;
    2. check whether the report is in scope;
    3. validate whether the reported issue represents a vulnerability;
    4. assess severity, exploitability, affected products, and potential impact;
    5. identify mitigations, workarounds, or remediation actions;
    6. coordinate internally between PSIRT, CSIRT, engineering, product management, support, legal, and other relevant functions;
    7. coordinate externally with the reporting entity, affected suppliers, customers, national CSIRT, ENISA, or other competent parties where appropriate;
    8. prepare public disclosure where required.
  • Public Disclosure

    Luna will publicly disclose validated and verified exploited or severe vulnerabilities within 90 days, unless Luna becomes aware of the vulnerability and fixes it before the affected product is placed on the market. The disclosure timing depends on technical feasibility, supplier cooperation and regulatory requirements.

    If there is a valid justification and explanation for a delay in mitigating or fixing the exploited or severe vulnerability, Luna may extend the disclosure period once by a further 90 days in close consultation with its corresponding national CSIRT. Further extensions may be possible only by the corresponding national CSIRT upon request.

    Where applicable, public disclosure may occur through:

    • Luna security advisories;
    • Luna CSAF security advisory publication;
    • the European Vulnerability Database — EUVD;
    • national CSIRT coordination channels;
    • other appropriate vulnerability databases or advisory channels.
  • Status Enquiries and Communication

    Luna welcomes reasonable status enquiries from reporting entities. Please include the original report reference, where available.

    Luna expects all involved parties to communicate respectfully. Discrimination, harassment, threats, insults, or other abusive behaviour are not acceptable.

  • Anonymous Reporting

    Luna provides an anonymous reporting option through its vulnerability reporting web form.

    Anonymous reports are accepted and assessed. However, Luna may be unable to fully process a report if:

    • the report lacks sufficient technical detail;
    • Luna cannot ask follow-up questions;
    • required evidence or reproduction steps are missing;
    • the reported issue affects third-party systems or environments that cannot be verified.

    Anonymous reports may therefore be processed only to a limited extent or possibly not at all if essential information is missing.

  • End of the CVD Process

    The CVD process is considered complete when one of the following conditions applies:

    • the reported indications are unfounded;
    • the vulnerability has been fixed or mitigated and publicly disclosed;
    • the vulnerability affects a service and the issue has been fixed and publicly disclosed;
    • the reporting entity has not responded to technical or content-related queries for at least 30 days, and the report can no longer be processed effectively;
    • the vulnerability has been publicly disclosed and, in consultation with the corresponding national CSIRT, it can no longer be assumed that the vulnerability will be mitigated or fixed.

    Where contact information is available, Luna will communicate the end of the CVD process to the reporting entity without undue delay.

  • Privacy Notice

    Personal data submitted as part of a vulnerability report will be processed only for the purpose of receiving, assessing, validating, coordinating, remediating, and disclosing the reported vulnerability.

    Schanzenstrasse 39, Bldg. D9-D13 51063 Cologne, Germany

    +49-22199887-0

    +49-22199887-150

    www.lunainc.com

    lios.lunainc.com 

    For further details, please refer to Luna’s privacy policy:

    Privacy policy: https://lunainc.com/privacy-policy

  • Related Security Resources
  • Review and Maintenance

    Luna will review this CVD policy at least annually and update it when necessary.

Vulnerability Reporting Form

Privacy & Safe Harbor Notice: In accordance with our CVD Policy, you may submit this report anonymously. We do not log IP addresses or browser fingerprints. If you conduct your research in good faith according to our guidelines, we will not pursue legal action against you.

Affected Product
Vulnerability Details
Helps us route the issue to the correct engineering team.
Provide exact steps so our team can verify the issue immediately.
For security reasons, executable files (.exe, .sh, .py, .zip) are not accepted via this form. Please paste code snippets into the text areas.
One file only.
50 MB limit.
Allowed types: txt, pdf, jpg, png, mp4.
Reporter Information (Optional)
Leave these blank to submit your report anonymously.
If you provide an email, include your PGP key so we can encrypt our replies to you.
Reach Out to Luna

Have a Question?