Skip to content
lantv.

SECURITY

Found a hole? Tell us.

Report it to lantv@fastmail.com and we will take it seriously. This page says what happens after you send it — what we look at, how long we take, and what we promise not to do to you for looking.

Sending the report

Where

Email lantv@fastmail.com. There is no bug bounty and no form to fill in — a plain email reaches a person. If you would rather encrypt it, say so in a first message and we will exchange keys.

What to put in it

Enough to reproduce it: the version, the platform, and the steps. A proof of concept is worth more than a description. If you are unsure whether something counts, send it anyway — deciding that is our job, not yours.

What not to do

Don’t test against anyone else’s installation, don’t access or alter data that isn’t yours, and don’t run anything that degrades the service for other people. Everything lantv does can be reproduced on a machine you own.

What happens next

We answer

You get a human reply within five working days, saying whether we could reproduce it and what we think it is. lantv is built by a very small team, so that is a real number rather than an optimistic one.

We keep you posted

You hear from us when the assessment changes and when a fix ships — not only at the end. If we decide something is not a vulnerability, we tell you why rather than going quiet.

We say it was you

Fixes are credited to the reporter by name or handle in the release notes, unless you would rather stay anonymous. Tell us which you want.

Coordinated disclosure

Please give us 90 days before publishing. If a fix lands sooner we will say so and you are free to publish then; if it needs longer, we will explain why rather than let the clock run out silently.

What is in scope

The lantv application

The desktop app, the server it runs on your network, and the browser client it serves — including the device gate, the licence check, and anything reachable over HTTP on your LAN.

api.lantv.app

The licensing and update service: checkout, licence issuing and validation, and the update feed. This is the only server of ours the app ever talks to.

lantv.app

This site.

Not in scope

How you have configured your own network or router; volumetric denial of service; social engineering of us or our suppliers; and missing hardening headers or best-practice findings with no demonstrated impact. Reports about our payment provider belong with them, not us.

Our side of it

Good-faith research is welcome

If you follow this policy while looking for problems, we will not pursue legal action against you or ask anyone else to. We consider that research authorised, and we will say so in writing if someone else questions it.

Regulatory reporting

As a product sold in the EU, lantv is subject to reporting duties for actively exploited vulnerabilities and severe incidents. We handle those obligations ourselves — reporting one never requires anything from you, and never identifies a reporter who asked to stay anonymous.