Reporting a vulnerability

Write to drimiun@drimiun.com and put "security" in the subject.

Banot is a LiDAR sprint-measurement system: a sensor running our own firmware, a phone app on iOS and Android, an Apple TV and Android TV scoreboard, an Apple Watch app, and a web application. If you have found something that affects the security of any of them, we want to hear about it.

Please include what you can: which component and version, what an attacker can do with it, and the steps to reproduce. If you would rather not send details by plain email, say so in a first message and we will arrange another channel.

What we will do

We ask for 90 days before public disclosure, and we will usually be much faster. If a fix is going to take longer than that, we will say so and explain why rather than let the deadline pass quietly.

What we ask of you

We will not take legal action over research done in good faith under this policy. Please do not access other people's data, degrade the service, or test against sensors and accounts that are not yours.

Where the fix arrives

Sensor firmware is signed and delivered over the air from inside the app, so a patched image reaches a sensor without anyone visiting it. Apps update through the App Store and Google Play. The web application and the cloud functions are deployed by us.

Regulatory reporting

Banot is a product with digital elements under Regulation (EU) 2024/2847, the Cyber Resilience Act. From 11 September 2026 we are required to notify ENISA of any actively exploited vulnerability and any severe incident affecting the security of the product: an early warning within 24 hours, the notification within 72 hours and the final report within 14 days.

Two consequences worth stating, because they change how a report is handled rather than merely recording an obligation. The 24-hour clock starts when we become aware, not when we finish triaging: a report that arrives on a Friday is acted on. And "actively exploited" is a different question from "severe", so a low-severity issue that is being exploited is reportable while a high-severity one that is not may not be. Both questions get asked of every report.

The machine-readable version of this page is at /.well-known/security.txt (RFC 9116).

Who answers

Drimiun Wireless Systems SL, tax ID B38950770, at Calle Quintíon Benito, 31 - La Laguna - Tenerife, Spain.