Vulnerability Disclosure Policy
We make infrastructure objects intelligent, and keeping them secure is a shared responsibility. If you have found a weakness in our Smart Lighting Controllers, we want to hear from you, and we will work with you to fix it.
Security is a continuous collaboration
At obiWAN Conobi Lda., we are committed to ensuring the safety, privacy and cybersecurity of our customers and the critical infrastructure driven by our Smart Lighting Controllers. We firmly believe that security is a continuous collaboration. We welcome and appreciate feedback from independent security researchers, ethical hackers, partners and customers who help us improve our cyber resilience.
This policy outlines the steps to report a suspected vulnerability in our products, what you can expect from us, and the safe harbour guidelines under which we operate.
Scope
This policy applies exclusively to cybersecurity vulnerabilities discovered in the assets listed below.
Hardware and Firmware
All active production versions of obiWAN Conobi Lda. Smart Lighting Controllers, including IoT modules and communication boards.
Web domains
obiwan-conobi.com and its subdomains.
What this policy does not cover
- Physical security attacks on our offices, facilities or production lines.
- Social engineering, phishing, or denial-of-service (DoS/DDoS) attacks against our infrastructure.
- Third party components, integrations or networks managed by our clients, unless the root cause is a defect in our product.
Our commitments
We treat all security reports with the highest priority and commit to the following standard timeline.
-
3dWithin 3 business days
Acknowledgment
We confirm receipt of your report and assign it to our engineering team.
-
10dWithin 10 business days
Triage and validation
We analyse the technical details, confirm the vulnerability and assign a CVSS severity level.
-
90dTarget: 90 days
Remediation
We develop, test and deploy a firmware patch or workaround. Complex supply chain or hardware dependencies may require an extension, communicated transparently.
-
✓After public release
Attribution
Once a fix is available and publicly released, we gladly credit you in our Security Advisory or Release Notes, unless you prefer to remain anonymous.
compliance
EU Cyber Resilience Act (CRA)
If an actively exploited vulnerability or a severe incident is confirmed, obiWAN Conobi Lda. will formally notify ENISA and the designated national CSIRT within the mandatory reporting windows.
Guidelines and safe harbour
We want to support and protect researchers who act in good faith. obiWAN Conobi Lda. will not pursue legal action or report you to law enforcement if you adhere to the following principles.
-
01
No extortion
You must not demand financial compensation, rewards or licences as a condition for disclosing the vulnerability. We do not operate a monetary bug bounty programme at this time.
-
02
No disruption
Avoid testing methods that could degrade, disrupt or crash our customers’ live operational systems, for example public street lighting networks.
-
03
Data protection
If you accidentally access personal data or proprietary telemetry during your research, do not view, download, alter or retain it. Delete any copies immediately.
-
04
Coordinated disclosure
You agree to keep all technical details of the vulnerability confidential until we have successfully deployed a security patch or mitigation for our users.
Submit a vulnerability report
If you believe you have found a potential security vulnerability, please report it to us as soon as possible using the form below. The more detail you provide, the faster we can validate and fix it.
If you would rather not use the form, write to security@obiwan-conobi.com. The same commitments and safe harbour guidelines apply.