Security at VUMO

VUMO runs a coordinated vulnerability disclosure and allows researchers, customers, partners, suppliers, and authorities to responsibly report findings. No account or contract is needed to use it.

Report a vulnerability

Pick whichever channel suits you: the form below or a phone call (the number is shown under the form). Every report gets a reference number and a reply from a person, so you will have an address to send screenshots or proof-of-concept files to. We accept reports in English and Polish.

Useful to include: description of the problem, affected product or hostname and version, what the issue allows and from where, steps to reproduce, and how you want to be credited.

Report before you publish. Do not include VUMO customer or third-party data.

We will acknowledge the reported issue within up to 5 business days.

No attachments here. Once we reply, send screenshots or proof-of-concept files in that e-mail thread. You can also paste links (video, gist) in the description.

We use the details you send only to handle your report and to reply to you.

Scope

In this policy, VUMO Robots means the following devices:

  • VUB (Vumo Underbody) — the underbody inspection station, base unit and Gate variant, including its firmware, on-device services and operator interface.
  • VST (Vumo Station) — including its firmware, on-device services and operator interface.

In scope:

  • Every VUMO Robot.
  • The operator web application.
  • Our web services auth.vumo.ai / api.scans.vumo.ai and their subdomains.
  • The mechanism by which updates reach deployed VUMO Robots.

Out of scope: any VUMO Robot or network you do not own, if you are a customer and want to test your own unit, contact us through the form first, physical hardware attacks you do not own, anything involving vehicles, moving parts or a live inspection lane, denial of service and load testing, social engineering and physical intrusion, third-party infrastructure VUMO does not control, though our configuration of it is in scope.

Normally closed as informational: missing headers, cookie flags, or TLS options with no demonstrated impact, raw scanner output, missing SPF/DKIM/DMARC on non-mail domains, version banners, CVEs where the vulnerable code path is not reachable in our configuration, issues needing a compromised operator device, an open cabinet, or an already-privileged administrator, self-XSS, clickjacking with no state change, end-of-life browsers.

Rules, and our commitment to you

Follow the rules below, and VUMO will not initiate or support legal or law-enforcement action against you for your research. We will treat your access as authorised, and say so if a third party claims otherwise.

  1. Test only in-scope systems, never a customer's installation.
  2. Stop at proof. No pivoting, no persistence.
  3. Leave data alone. If you hit personal, scan, or credential data, stop and tell us what you saw.
  4. No DoS, no destructive testing, nothing affecting a live inspection lane, a VUMO Robot in operation, or a vehicle.
  5. No extortion.
  6. Give us the disclosure window.
  7. Obey the law. This policy authorizes nothing unlawful.

We do not operate a paid bug bounty. We do give public credit.

Disclosure window

Up to 5 business days to acknowledge.

Up to 90 days from acknowledgment before you publish.

  • Publish when we do,
  • If we need longer, we'll tell you why and give you a date. No extension without a reason,
  • If the issue is being exploited or becomes public, the window ends, and we publish guidance immediately,
  • You may publish once the window expires. We will not use silence to keep an issue unpublished.

We credit reporters in advisories by default, in the form you ask for. Say if you prefer anonymity.

Advisories

Where a vulnerability affects a VUMO Robot, we publish the affected versions, the impact and severity, and what customers need to do. We notify customers with a deployed VUMO Robot directly. Please note that all our security updates are free.

Version 1.0, in force since September 2026