Our commitment
K|Lens GmbH takes the security of our machine vision products, software, and web properties seriously. We value the work of security researchers and customers who help us identify and resolve vulnerabilities responsibly, and we are committed to working with you to understand and address any issue quickly.
Scope
This policy applies to:
- The k-lens.ai website and associated web applications
- K|Lens vision components and complete vision systems (hardware and firmware/software)
- Any customer-facing software or interfaces we provide as part of our products
Out of scope: third-party services we link to but do not operate, and social media accounts.
How to report a vulnerability
If you believe you have found a security vulnerability, please report it to us directly rather than disclosing it publicly.
Email: security@k-lens.de
Contact form: k-lens.ai/contact
We do not currently offer PGP-encrypted email. Please avoid including highly sensitive personal data in your report; a description of the issue and reproduction steps is sufficient.
Please include, where possible:
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- The product, system, or URL affected, including version if known
- Any supporting material (screenshots, logs, proof-of-concept code)
What you can expect from us
- Acknowledgment of your report within 3 business days
- An initial assessment of the report and its severity within 10 business days
- Regular updates on our progress until the issue is resolved
- Credit, if you would like it, once the issue is fixed and disclosure is coordinated
Coordinated disclosure
We ask that you give us a reasonable opportunity to investigate and remediate an issue before making any information public. We aim to resolve critical issues promptly and will agree a disclosure timeline with you — typically within 90 days of your report, or sooner where possible.
Safe harbor
We will not pursue legal action against researchers who:
- Make a good faith effort to avoid privacy violations, data destruction, and service interruption
- Only interact with accounts or data they own, or with explicit permission from the account holder
- Do not exploit a vulnerability beyond what is necessary to confirm its existence
- Report the vulnerability to us promptly and do not disclose it publicly before we've had a chance to address it
Activity conducted consistent with this policy will be considered authorized, and we will not initiate legal action related to that activity.