Security & Vulnerability Disclosure
A clear reporting path for suspected vulnerabilities in LUXION public systems.
Security reports should be precise, minimally invasive, and coordinated.
Scope
This reporting channel covers suspected vulnerabilities in LUXION-controlled public web surfaces, including ecoluxion.com and guardianpilot.org. It does not authorize testing of customer systems, third-party services, private repositories, production credentials, or infrastructure not explicitly made public by LUXION.
How to report
Email [email protected] with the subject Security report — LUXION public systems. Include only the information needed to understand and reproduce the issue safely.
- The affected domain, page, endpoint, or public asset.
- A concise description of the suspected vulnerability and potential impact.
- Reproduction steps that avoid accessing, modifying, retaining, or disclosing third-party data.
- Relevant request and response details with credentials, tokens, personal data, and confidential information removed.
- A preferred contact method for coordinated follow-up.
LUXION will acknowledge actionable reports where feasible and coordinate follow-up based on severity, reproducibility, and available remediation capacity. Response and remediation times vary by issue and do not constitute a service-level guarantee.
Testing boundaries
- Do not disrupt service availability, degrade performance, or perform denial-of-service testing.
- Do not access, alter, delete, retain, or disclose data that is not your own.
- Do not test customer, partner, cloud-provider, email-provider, analytics, or other third-party systems.
- Do not use social engineering, credential attacks, phishing, malware, or physical intrusion.
- Stop testing and report promptly if sensitive information becomes visible.
This page is not a bug-bounty program, a promise of payment, or authorization for disruptive, unlawful, or third-party testing. Nothing here limits obligations imposed by applicable law.
Disclosure coordination
Please allow reasonable time to investigate and remediate a verified issue before public disclosure. LUXION may request clarification, additional non-sensitive evidence, or a retest of a proposed fix. Reports that contain sensitive data should be minimized and redacted.
Machine-readable contact information is available at /.well-known/security.txt in the format defined by RFC 9116.
Policy status
Published: 28 July 2026. This policy may be revised as LUXION's public systems, reporting processes, and operational capacity evolve.