Vulnerability Disclosure

Product Security · Coordinated Disclosure

Vulnerability Disclosure Policy

We make infrastructure objects intelligent, and keeping them secure is a shared responsibility. If you have found a weakness in our Smart Lighting Controllers, we want to hear from you, and we will work with you to fix it.

Last update August 2026 Issued by obiWAN Conobi Lda. Aligned with the EU Cyber Resilience Act

Security is a continuous collaboration

At obiWAN Conobi Lda., we are committed to ensuring the safety, privacy and cybersecurity of our customers and the critical infrastructure driven by our Smart Lighting Controllers. We firmly believe that security is a continuous collaboration. We welcome and appreciate feedback from independent security researchers, ethical hackers, partners and customers who help us improve our cyber resilience.

This policy outlines the steps to report a suspected vulnerability in our products, what you can expect from us, and the safe harbour guidelines under which we operate.

Scope

This policy applies exclusively to cybersecurity vulnerabilities discovered in the assets listed below.

In scope

Hardware and Firmware

All active production versions of obiWAN Conobi Lda. Smart Lighting Controllers, including IoT modules and communication boards.

Web domains

obiwan-conobi.com and its subdomains.

obiWAN LAMPYRiS IoT modules Communication boards Production firmware obiwan-conobi.com
Out of scope

What this policy does not cover

  • Physical security attacks on our offices, facilities or production lines.
  • Social engineering, phishing, or denial-of-service (DoS/DDoS) attacks against our infrastructure.
  • Third party components, integrations or networks managed by our clients, unless the root cause is a defect in our product.

Our commitments

We treat all security reports with the highest priority and commit to the following standard timeline.

  1. 3d
    Within 3 business days

    Acknowledgment

    We confirm receipt of your report and assign it to our engineering team.

  2. 10d
    Within 10 business days

    Triage and validation

    We analyse the technical details, confirm the vulnerability and assign a CVSS severity level.

  3. 90d
    Target: 90 days

    Remediation

    We develop, test and deploy a firmware patch or workaround. Complex supply chain or hardware dependencies may require an extension, communicated transparently.

  4. After public release

    Attribution

    Once a fix is available and publicly released, we gladly credit you in our Security Advisory or Release Notes, unless you prefer to remain anonymous.

Regulatory
compliance

EU Cyber Resilience Act (CRA)

If an actively exploited vulnerability or a severe incident is confirmed, obiWAN Conobi Lda. will formally notify ENISA and the designated national CSIRT within the mandatory reporting windows.

Early warning · 24 hours Vulnerability notification · 72 hours

Guidelines and safe harbour

We want to support and protect researchers who act in good faith. obiWAN Conobi Lda. will not pursue legal action or report you to law enforcement if you adhere to the following principles.

  1. 01

    No extortion

    You must not demand financial compensation, rewards or licences as a condition for disclosing the vulnerability. We do not operate a monetary bug bounty programme at this time.

  2. 02

    No disruption

    Avoid testing methods that could degrade, disrupt or crash our customers’ live operational systems, for example public street lighting networks.

  3. 03

    Data protection

    If you accidentally access personal data or proprietary telemetry during your research, do not view, download, alter or retain it. Delete any copies immediately.

  4. 04

    Coordinated disclosure

    You agree to keep all technical details of the vulnerability confidential until we have successfully deployed a security patch or mitigation for our users.

Submit a vulnerability report

If you believe you have found a potential security vulnerability, please report it to us as soon as possible using the form below. The more detail you provide, the faster we can validate and fix it.

Direct contact

If you would rather not use the form, write to security@obiwan-conobi.com. The same commitments and safe harbour guidelines apply.


    Please do not include exploit code, customer data or personal data in this form.
    If your report requires sensitive attachments, tell us in the description and we will provide a secure channel.





    2. Vulnerability type *


    E.g. obiWAN LAMPYRiS, NB-IoT/LTE-M Zhaga Outdoor Lighting Controller, or obiwan-conobi.com


    What is the weakness, where does it sit, and what could an attacker achieve?


    Include the setup used, the sequence of steps, and any tooling. Do not test against live public lighting systems.




    Optional. Logs, screenshots or packet captures, max 2 MB (pdf, txt, log, png, jpg, zip).

    9. Attribution preference

    Your report is handled by our Product Security team. Personal data submitted here is processed solely to triage and resolve the reported issue.

    Thank you for helping us keep our connected lighting infrastructure safe and secure.

    obiWAN Conobi Lda. · Product Security
    Cart (0 items)
    Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
    • Image
    • SKU
    • Rating
    • Price
    • Stock
    • Availability
    • Add to cart
    • Description
    • Content
    • Weight
    • Dimensions
    • Additional information
    Click outside to hide the comparison bar
    Compare