Responsible Disclosure
Last updated:
Responsible Disclosure Policy
Last updated: 1 August 2026 | Version 1.0
Lumetrix BV welcomes reports from security researchers and users who discover potential security vulnerabilities. This policy explains how to report them safely.
How to Report
E-mail security@lumetrix.tv with a clear description of the issue, the affected component or URL, steps to reproduce, and any proof-of-concept. Please encrypt sensitive details if possible. A machine-readable version of this contact is published at lumetrix.tv/.well-known/security.txt.
Our Commitment
- We will acknowledge your report within 5 business days.
- We will investigate and keep you reasonably informed of progress.
- We will not pursue legal action against researchers who act in good faith and follow this policy.
- We will credit you (with your permission) once an issue is resolved.
Guidelines (Good-Faith Research)
- Do not access, modify or delete data that is not yours; use only test accounts you control.
- Do not degrade the Service (no denial-of-service, spam or automated high-volume testing).
- Do not publicly disclose the issue until we have had a reasonable time to fix it and have agreed on disclosure.
- Comply with all applicable laws.
Out of Scope
Reports about third-party services users connect (such as external IPTV sources or streaming apps) are out of scope, as we do not control them.