Security
Vulnerability reporting and coordinated disclosure · Version 2026-09-08
Report privately: email support [at] lumadeck.app with the subject SECURITY. We aim to acknowledge reports within three business days.
What to include
Tell us the affected product and version, impact, reproducible steps and any safe proof of concept. Include logs or screenshots only after removing credentials, licence tokens, personal data and third-party content. Do not send secrets through public issues or social media.
Scope
This process covers lumadeck.app, its first-party APIs and LumaDeck Output Bridge. Vulnerabilities in NDI®, Stripe, browsers or other third-party products should also be reported to their publisher; tell us privately if they materially affect LumaDeck.
Good-faith research
Use only accounts and systems you own or have explicit permission to test. Do not access other users' data, disrupt production, perform denial of service, use social engineering or retain data beyond what is strictly needed to demonstrate the issue. Stop and report if you encounter personal data. We will not pursue legal action for good-faith research that respects these rules and applicable law.
What happens next
We triage the report, preserve evidence, coordinate a fix and communicate material mitigation or update instructions. Please allow reasonable time before public disclosure. This is not a bug-bounty programme and no payment is promised. Statutory reporting to authorities and affected users is handled separately when required.
NDI® is a registered trademark of Vizrt NDI AB. Learn more at ndi.video.
Seguridad
Comunicación de vulnerabilidades y divulgación coordinada · Versión 2026-09-08
Comunicación privada: escribe a support [at] lumadeck.app con el asunto SECURITY. Intentaremos acusar recibo en tres días laborables.
Qué debes incluir
Indica el producto y versión afectados, el impacto, pasos reproducibles y una prueba de concepto segura si procede. Adjunta logs o capturas solo después de eliminar credenciales, tokens de licencia, datos personales y contenido de terceros. No envíes secretos por incidencias públicas ni redes sociales.
Ámbito
Este proceso cubre lumadeck.app, sus API propias y LumaDeck Output Bridge. Las vulnerabilidades de NDI®, Stripe, navegadores u otros productos de terceros también deben comunicarse a su editor; avísanos en privado si afectan materialmente a LumaDeck.
Investigación de buena fe
Usa solo cuentas y sistemas propios o para los que tengas permiso expreso. No accedas a datos de otros usuarios, interrumpas producción, realices denegación de servicio, uses ingeniería social ni conserves datos más allá de lo imprescindible para demostrar el problema. Detente y comunícalo si encuentras datos personales. No emprenderemos acciones legales contra una investigación de buena fe que respete estas reglas y la ley aplicable.
Qué ocurre después
Clasificamos el aviso, preservamos pruebas, coordinamos la corrección y comunicamos las medidas o actualizaciones importantes. Permite un tiempo razonable antes de divulgar públicamente. Esto no es un programa de recompensas y no se promete pago. Las notificaciones legales a autoridades y usuarios afectados se gestionan por separado cuando resulten obligatorias.
NDI® es una marca registrada de Vizrt NDI AB. Más información en ndi.video.