Vulnerability Disclosure

Product Security & Vulnerability Disclosure

At Lyras, the safety and security of our Raslysation™ systems is a core commitment. Our equipment operates in food, beverage, and pharmaceutical production environments, and we take the security of its hardware, software, and connectivity seriously.

We welcome reports from security researchers, customers, partners, and authorities about potential security vulnerabilities in our products or services. This page describes how to report a vulnerability to us and what you can expect in return. This policy constitutes our coordinated vulnerability disclosure (CVD) policy in accordance with the EU Cyber Resilience Act.

How to report a vulnerability

If you believe you have found a security vulnerability in a product or software supplied by Lyras, please fill the form below or contact us at:

[email protected]

Please include, where possible:

  • A description of the vulnerability and its potential impact
  • The product, software version, serial number (e.g. Raslysation™ Spica, including control-system version if known)
  • Steps to reproduce the issue, proof-of-concept, or supporting material (screenshots, logs)
  • Your name and contact details for follow-up — anonymous reports are also accepted

Scope

All Lyras Raslysation™ products including control systems and firmware, software and services provided by Lyras.

Vulnerabilities in third-party components (e.g. control hardware) as integrated in a Lyras system are in scope — we assess the impact on our products and coordinate remediation with the component manufacturer.
Generic vulnerabilities in third-party products unrelated to a Lyras system should be reported directly to the relevant manufacturer.

Our commitment

  • Acknowledgement within 3 business days, assessment within 10
  • Status updates until the issue is resolved (requires that an email has been provided)
  • Security updates addressing vulnerabilities in supported products are provided free of charge and without undue delay.
  • Affected customers are informed directly; authorities are notified where required

Coordinated disclosure

We ask that you give us a reasonable opportunity to remediate a vulnerability before any public disclosure. Our standard coordination window is 90 days from acknowledgement; where remediation requires on-site service of installed machinery, we may ask for a reasonable extension and will keep you informed of progress. We will always coordinate the timing and content of any public disclosure with you.

Ground rules (safe harbour)

We will not initiate legal action against researchers who, in good faith:

  • Report vulnerabilities promptly through the contact point above
  • Make every effort to avoid privacy violations, data destruction, and disruption of production systems
  • Do not access, modify, or delete data beyond what is necessary to demonstrate the vulnerability
  • Do not exploit the vulnerability beyond proof-of-concept, and keep details confidential until coordinated disclosure

Please note that Lyras systems operate in live production at customer sites. Never test against installed systems in operation — doing so may endanger product safety and is outside the protection of this policy. If you have access to a Lyras system and wish to perform security testing, contact us first and we will find a safe way to facilitate it.

Out of scope

The following are not considered reportable vulnerabilities under this policy:

  • Findings from automated scanners without a demonstrated security impact
  • Lyras products marketed by third parties under their own brand, or modified beyond Lyras specifications.
  • Vulnerabilities in third-party services not operated by Lyras

For product support and non-security enquiries, please use our contact page.

Version 2026.1 – Last updated 1 September 2026 

Submit a vulnerability report