Security & Vulnerability Disclosure

A clear reporting path for suspected vulnerabilities in LUXION public systems.

Security reports should be precise, minimally invasive, and coordinated.

Scope

This reporting channel covers suspected vulnerabilities in LUXION-controlled public web surfaces, including ecoluxion.com and guardianpilot.org. It does not authorize testing of customer systems, third-party services, private repositories, production credentials, or infrastructure not explicitly made public by LUXION.

How to report

Email [email protected] with the subject Security report — LUXION public systems. Include only the information needed to understand and reproduce the issue safely.

  • The affected domain, page, endpoint, or public asset.
  • A concise description of the suspected vulnerability and potential impact.
  • Reproduction steps that avoid accessing, modifying, retaining, or disclosing third-party data.
  • Relevant request and response details with credentials, tokens, personal data, and confidential information removed.
  • A preferred contact method for coordinated follow-up.

LUXION will acknowledge actionable reports where feasible and coordinate follow-up based on severity, reproducibility, and available remediation capacity. Response and remediation times vary by issue and do not constitute a service-level guarantee.

Testing boundaries

  • Do not disrupt service availability, degrade performance, or perform denial-of-service testing.
  • Do not access, alter, delete, retain, or disclose data that is not your own.
  • Do not test customer, partner, cloud-provider, email-provider, analytics, or other third-party systems.
  • Do not use social engineering, credential attacks, phishing, malware, or physical intrusion.
  • Stop testing and report promptly if sensitive information becomes visible.

This page is not a bug-bounty program, a promise of payment, or authorization for disruptive, unlawful, or third-party testing. Nothing here limits obligations imposed by applicable law.

Disclosure coordination

Please allow reasonable time to investigate and remediate a verified issue before public disclosure. LUXION may request clarification, additional non-sensitive evidence, or a retest of a proposed fix. Reports that contain sensitive data should be minimized and redacted.

Machine-readable contact information is available at /.well-known/security.txt in the format defined by RFC 9116.

Policy status

Published: 28 July 2026. This policy may be revised as LUXION's public systems, reporting processes, and operational capacity evolve.