Reporting a vulnerability
Last updated: 5 September 2026
Write to drimiun@drimiun.com and put "security" in the subject.
Banot is a LiDAR sprint-measurement system: a sensor running our own firmware, a phone app on iOS and Android, an Apple TV and Android TV scoreboard, an Apple Watch app, and a web application. If you have found something that affects the security of any of them, we want to hear about it.
Please include what you can: which component and version, what an attacker can do with it, and the steps to reproduce. If you would rather not send details by plain email, say so in a first message and we will arrange another channel.
What we will do
- Acknowledge within 3 working days. If you do not hear from us, assume the mail was lost and try again.
- Tell you our assessment within 10 working days — whether we can reproduce it, how severe we think it is, and roughly when a fix will ship.
- Keep you updated until it is fixed, and credit you when we publish, unless you would rather we did not.
We ask for 90 days before public disclosure, and we will usually be much faster. If a fix is going to take longer than that, we will say so and explain why rather than let the deadline pass quietly.
What we ask of you
We will not take legal action over research done in good faith under this policy. Please do not access other people's data, degrade the service, or test against sensors and accounts that are not yours.
Where the fix arrives
Sensor firmware is signed and delivered over the air from inside the app, so a patched image reaches a sensor without anyone visiting it. Apps update through the App Store and Google Play. The web application and the cloud functions are deployed by us.
Regulatory reporting
Banot is a product with digital elements under Regulation (EU) 2024/2847, the Cyber Resilience Act. From 11 September 2026 we are required to notify ENISA of any actively exploited vulnerability and any severe incident affecting the security of the product: an early warning within 24 hours, the notification within 72 hours and the final report within 14 days.
Two consequences worth stating, because they change how a report is handled rather than merely recording an obligation. The 24-hour clock starts when we become aware, not when we finish triaging: a report that arrives on a Friday is acted on. And "actively exploited" is a different question from "severe", so a low-severity issue that is being exploited is reportable while a high-severity one that is not may not be. Both questions get asked of every report.
The machine-readable version of this page is at /.well-known/security.txt (RFC 9116).
Who answers
Drimiun Wireless Systems SL, tax ID B38950770, at Calle Quintíon Benito, 31 - La Laguna - Tenerife, Spain.