← Back to LumaDeck

Security

Vulnerability reporting and coordinated disclosure · Version 2026-09-08

Report privately: email support [at] lumadeck.app with the subject SECURITY. We aim to acknowledge reports within three business days.

What to include

Tell us the affected product and version, impact, reproducible steps and any safe proof of concept. Include logs or screenshots only after removing credentials, licence tokens, personal data and third-party content. Do not send secrets through public issues or social media.

Scope

This process covers lumadeck.app, its first-party APIs and LumaDeck Output Bridge. Vulnerabilities in NDI®, Stripe, browsers or other third-party products should also be reported to their publisher; tell us privately if they materially affect LumaDeck.

Good-faith research

Use only accounts and systems you own or have explicit permission to test. Do not access other users' data, disrupt production, perform denial of service, use social engineering or retain data beyond what is strictly needed to demonstrate the issue. Stop and report if you encounter personal data. We will not pursue legal action for good-faith research that respects these rules and applicable law.

What happens next

We triage the report, preserve evidence, coordinate a fix and communicate material mitigation or update instructions. Please allow reasonable time before public disclosure. This is not a bug-bounty programme and no payment is promised. Statutory reporting to authorities and affected users is handled separately when required.

NDI® is a registered trademark of Vizrt NDI AB. Learn more at ndi.video.