• Lepton System Vulnerability Disclosure Policy


    Lepton Systems is committed to ensuring the security and integrity of our physical layer switches. We welcome feedback from security researchers and the broader community to help us identify and remediate vulnerabilities in our products. This Vulnerability Disclosure Policy outlines the scope, rules of engagement, and process for reporting potential security issues to our engineering team.

    ### Scope

    This policy applies **exclusively** to the proprietary Lepton Systems software and firmware running on the following product lines:

    * Lepton ColdFusion family of products
    * Lepton LightFusion family of products

    **Out of Scope (Customer IT Responsibility):**
    Lepton Systems ColdFusion and LightFusion products are deployed on standard, off-the-shelf Linux distributions (such as Ubuntu Server or Red Hat Enterprise Linux). Lepton Systems is strictly not responsible for vulnerabilities, recurring software updates, or patches related to:

    * The underlying host operating system (Ubuntu, RHEL, etc.).
    * Third-party libraries, packages, or tools provided natively by the OS.
    * Any customer-installed software, agents, or network configurations outside the Lepton application stack.

    Maintenance, patching, and security hardening of the host operating system and its native dependencies remain the sole responsibility of the customer's IT organization, in accordance with their internal security and update policies. Reports regarding OS-level vulnerabilities (e.g., standard kernel exploits, SSH daemon vulnerabilities) should be directed to the respective OS vendor, not Lepton Systems.

    ### Reporting a Vulnerability

    If you believe you have discovered a vulnerability in the in-scope Lepton software or firmware, please submit a report to **support@leptonsys.com**.

    To help our engineering team triage and reproduce the issue efficiently, please include the following in your report:

    * A detailed description of the vulnerability and its potential impact.
    * The specific product (ColdFusion or LightFusion) and the software/firmware version tested.
    * Step-by-step instructions to reproduce the issue (including any necessary proof-of-concept code or network capture logs).

    ### Our Commitment

    When you submit a vulnerability report in accordance with this policy, Lepton Systems commits to the following communication timescales:

    * **Acknowledgement:** We will acknowledge receipt of your vulnerability report within **72 hours**.
    * **Assessment & Timeline:** We will provide an initial assessment of the issue and a projected timeline for remediation within **30 days** of the initial acknowledgement.
    * **Transparency:** We will notify you when the vulnerability has been successfully patched or mitigated within our application stack.

    ### Rules of Engagement

    To maintain a safe testing environment and protect our customers, we simply ask that you:

    * Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services (including Denial of Service attacks).
    * Restrict your testing to hardware that you legally own or have explicit permission to test.
    * Avoid physical attacks, social engineering, or phishing against Lepton Systems personnel, facilities, or customers.
    * Allow us a reasonable opportunity to address the vulnerability before you disclose it publicly.

    ### Safe Harbor

    Lepton Systems considers security research and vulnerability disclosure conducted in good faith to be authorized conduct. We want you to feel comfortable reporting issues to us without fear of legal retaliation.

    If you conduct your research and report vulnerabilities in accordance with this policy:

    * We will not initiate any civil lawsuit or law enforcement investigation against you.
    * We waive any restrictions in our Terms of Service, End User License Agreements (EULA), or policies that would otherwise prohibit you from conducting security research or reverse-engineering our firmware for this purpose.
    * If legal action is initiated by a third party against you in connection with your good faith participation in this program, we will explicitly state that your actions were conducted with our authorization and in compliance with this policy.