Security

Reporting a security vulnerability

We welcome reports of security vulnerabilities in our products and services. If you have found something, please tell us about it.

Contact: security@laud-media.com

What to include

What you found, what product, and where it is — the store, or the address of the service. We need enough detail for us to reproduce it. If you have a proof of concept, please include it. Reports in English or Norwegian are equally welcome.

What we will do

  • Acknowledge your report within two working days
  • Give you an initial assessment, including whether we consider it a vulnerability, within ten working days
  • Keep you informed while we work on a fix, and tell you when it ships
  • Credit you publicly if you would like us to, or keep your report confidential if you prefer

What we ask of you

  • Give us a reasonable opportunity to fix the issue before disclosing it publicly. Our default is 90 days from your report, and we are happy to discuss it if that does not fit the situation
  • Do not access, modify or delete data belonging to our customers or their visitors
  • Do not degrade our services or the equipment in our customers' stores
  • Do not use social engineering, physical attacks, or attacks against our staff

Our commitment to you

If you research in good faith and within these guidelines, we will not pursue or support legal action against you, and we will treat your report as an act of assistance. If a third party brings action against you for work carried out under this policy, we will make that position known.

Scope

Our products and services. Findings in third-party components are in scope if they affect our products.

We do not operate a bug bounty programme. We cannot offer payment, and we would still like to hear from you.

Something not right with our products?

This is for our customers and for employees working in stores. If you research security professionally, the vulnerability disclosure policy is for you.

If something about our products or services looks wrong, it might be a security problem. You do not have to be certain, and you do not have to know what it is. A report that turns out to be nothing costs us very little. One that never gets sent can be worse.

Write to security@laud-media.com

Worth telling us about

  • A player showing content nobody scheduled - anything unexpected, wrong, or offensive on screen
  • A device asking for a password, an update or a confirmation that nobody was expecting
  • Someone contacting the store claiming to be from Laud Media and asking for the store password, or for access to a player
  • A player that has been opened or tampered with, or has something plugged into it that should not be there
  • Anything a colleague or a shopper noticed that could not be explained

What helps us

Which store, roughly when it started, what you saw, and a photograph of the screen. If you only have one of those, send that one - please do not wait until you have collected the rest.

One thing we ask

If you can, leave the player as it is until we have looked at it - a factory reset or a reinstall erases what we need to understand what happened.

But if the screen is showing something that must not be on display, switch it off or unplug it. That is the right call, and it always comes first. Just tell us you did it.

What happens next

  • We confirm we have your report within two working days
  • We will keep you updated on what happens, even if it turns out to be nothing
  • If it affects other customers, we tell them too. That is an obligation we carry, not a courtesy

One limitation, stated plainly

This address is monitored on working days. A report sent on a Friday evening may not be read until Monday.

If something needs a response sooner than that, use your normal Laud Media support contact as well — do not choose between them, use both.

This address reaches the people responsible for product security at Laud Media AS.