Product Security Vulnerability Reporting

Product security is part of how we design and manufacture at LDA. This is the channel for reporting any vulnerability you’ve identified.

How to report

LDA Audio Tech welcomes the responsible reporting of potential vulnerabilities or security issues that may affect its products, components, firmware, software or related technical product documentation.

If you believe you have identified a potential security vulnerability related to an LDA product, you may report it by email:

LDA’s usual customer support channels may also be used. When a received communication relates to product security, it will be handled internally through the same formal management process.

Information to include

Minimum information

To speed up our analysis, please include the following information in your report:

  • Affected product, component or service.
  • Affected version, firmware, software or configuration, if known.
  • A clear description of the observed issue.
  • Known or potential impact.
  • Contact details of the reporter for follow-up questions.

Additional information

If available, this information also helps us assess the case faster:

  • Detection method or context in which the issue was identified.
  • Conditions under which the issue can be reproduced, if known.
  • Reproduction steps, if available.
  • Available evidence such as logs, screenshots, traces, or proof of concept.
  • Whether the vulnerability or issue has already been publicly disclosed, in full or in part.

How we handle your report

External communications related to product security vulnerabilities or incidents are internally registered in LDA’s management system and are handled according to the applicable internal procedures and instructions.

Here’s the internal process we follow once we receive your report:

  1. Registration and traceability of the received communication.
  2. Technical analysis and evaluation of scope and impact.
  3. Definition of correction, containment, mitigation, or compensating measures, where appropriate.
  4. Verification of the effectiveness of the measures taken.
  5. Determination of any additional communications required to customers, users, other interested parties, or competent authorities, where applicable.

Coordinated disclosure

LDA promotes a coordinated vulnerability disclosure approach intended to allow the reported information to be analyzed, evaluated, and appropriately handled before public disclosure, whenever compatible with the protection of customers, users, and other interested parties.

Where appropriate, LDA may publish support information, mitigations, advisories, or instructions through the LDA support website and its usual customer support channels.

Scope

This channel is intended for vulnerabilities or security issues related to products with digital elements, components, firmware, software, product-related services, or technical documentation related to product security.

Commercial, logistics, administrative, or non-security support matters should preferably be sent through LDA’s usual customer support channels.

Do you have information about a potential security vulnerability? Get in touch.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.