Vulnerability disclosure policy

1. Introduction and Lainox's commitment

Lainox – Ali Group Srl ("Lainox") places great importance on the security of its connected products and welcomes contributions from independent security researchers. This document describes how to responsibly report a suspected security vulnerability affecting Lainox products, and what to expect from Lainox once a report has been received.

This policy is also published in Italian; in the event of any discrepancy between the two versions, the Italian version shall prevail.

2. Scope

The following are in scope for this policy:

• Lainox devices equipped with Wi-Fi and/or cloud connectivity: Naboo 5, Naboo Boosted, Naboo Reloaded, Neo24hours, Oracle, Puff/Foody, and future connected products developed by Lainox.

• Lainox digital infrastructure: web and cloud systems directly operated by Lainox in support of these products (e.g. the service-planner.lainox.it portal).

The following are out of scope for this policy:

• Third-party services and components: services, components, or infrastructure of third parties not directly controlled by Lainox, even where used in combination with Lainox products.

• Invasive or destructive testing: physical attacks on machines already installed at customer sites, social engineering against Lainox staff, customers or distributors, and testing that causes denial of service on devices in active use by customers.

3. How to report a vulnerability

Reports can be submitted through:

• Email: service@lainox.com — primary channel, available 24 hours a day, 7 days a week. Please include "Security Vulnerability Report – [product/model]" in the subject line.

• Phone: +39 0438 911999 — for urgent reports involving potentially critical impact.

To allow a fast and effective assessment, please include in your report, as far as possible:

• the affected product/model and firmware/software version;

• a detailed description of the vulnerability and its potential impact;

• the steps needed to reproduce it (proof of concept, if available);

• a contact address for any follow-up questions.

Upon request, an encrypted communication channel can be arranged for sharing particularly sensitive information.

 

 

4. What to expect from Lainox

Once a report is received, Lainox is committed to following this process:

Stage

Indicative timeframe*

Acknowledgement of receipt

Within 5 business days

Initial assessment (triage) and severity scoring (CVSS v3.1)

Within 30 calendar days of receipt

Status updates, for confirmed reports still being worked on

At least every 30 days

Coordinated disclosure

Until a fix is available, or in any case no later than 90 days after the vulnerability is confirmed, unless otherwise agreed with the reporter

* These timeframes represent a reference commitment (in line with industry practice, cf. ISO/IEC 29147 and 30111) and may vary depending on the complexity of the case; the reporter is kept informed of progress regardless.

Vulnerabilities confirmed as actively exploited, or serious security incidents, are handled and — where required — notified to the competent authorities in accordance with Regulation (EU) 2024/2847 (Cyber Resilience Act), following Lainox's internal vulnerability management process.

At the reporter's request, and where appropriate, Lainox may publicly acknowledge the researcher's contribution in a security advisory. A paid bug bounty programme is not currently offered.

5. Commitment to good-faith reporters

Lainox will not pursue legal action against anyone who reports a vulnerability in good faith and in accordance with this policy. Security researchers are asked to follow these guidelines:

• do not access, modify, or delete data beyond what is strictly necessary to demonstrate the existence of the vulnerability;

• do not conduct testing that could compromise the availability, integrity, or operational safety of devices in use at customer sites (Lainox ovens are professional foodservice equipment: testing must not interfere with their operation);

• do not exploit a vulnerability beyond what is necessary to confirm it, and avoid large-scale automated scanning that could impact Lainox or customer systems;

• give Lainox reasonable time to investigate and remediate the vulnerability before any public disclosure, consistent with Section 4;

• do not engage in social engineering, physical attacks, or denial-of-service testing.

6. Contact

Email: service@lainox.com

Phone: +39 0438 911999

Lainox – Ali Group Srl, Via Schiaparelli 15, Z.I. S.Giacomo di Veglia, 31029 Vittorio Veneto (TV), Italy

7. Policy updates

This policy is reviewed at least annually, or following relevant regulatory changes or significant changes to Lainox's vulnerability management processes. Each newly published version carries its version number and effective date.