Security & Vulnerability Disclosure

At NLIR, we take the security of our products and customers seriously. On this page, we describe how we handle product security, including vulnerabilities and security updates, in order to comply with applicable laws and regulations.

Report a Vulnerability

If you believe you have identified a security vulnerability in one of our products, report it to:

info@nlir.com

Please include, where possible:

  • The affected product and version
  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential security issue
  • Any relevant technical details or proof of concept

We ask that you report vulnerabilities responsibly, and give us reasonable time to investigate and address them, before publicly disclosing them.

Our Response

We will:

  • Review and assess the reported vulnerability
  • Determine its severity and potential impact
  • Investigate and, where appropriate, provide a corrective or mitigating measure
  • Communicate with the reporter where contact information has been provided
  • Coordinate disclosure with the reporter where appropriate

Scope

This policy applies to security vulnerabilities affecting NLIR’s products with digital elements, including associated firmware, software, APIs and other software components supplied as part of those products.

Security Updates

When a security vulnerability is identified, we assess its impact and, where appropriate, provide a security update or other mitigation.

Security updates are distributed through the normal update mechanism for the product. We recommend keeping our products up to date.

EU Cyber Resilience Act

We are committed to complying with the requirements applicable to our products under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

We maintain processes for handling security vulnerabilities, providing security updates, and addressing cybersecurity risks throughout the applicable product lifecycle.

Contact

For security-related matters: