Legal Directory
BreaktroughF1 LLP

Responsible Disclosure

Effective: May 2, 2026|Version: 1.0

Guidelines for security researchers reporting vulnerabilities in LYNX to BreaktroughF1 LLP.

We are committed to fixing legitimate security vulnerabilities responsibly. If you have found a vulnerability, please disclose it to us privately before public disclosure.

1. Our Commitment

We welcome reports from the security research community and commit to:

Acknowledging receipt within 2 business days

Providing an initial triage assessment within 7 business days

Working with you on coordinated disclosure timing (typically 90 days)

Not pursuing legal action against researchers acting in good faith

2. Scope

In Scope

  • LYNX desktop & firmware
  • LYNX web dashboard
  • Federated Learning infrastructure
  • Authentication subsystems

Out of Scope

  • Social engineering / phishing
  • Denial-of-service (DoS) attacks
  • Third-party library 0-days
  • Physical hardware attacks

3. How to Report

Send your report to . Please include reproduction steps, proof-of-concept code, and affected versions.

4. Rules of Engagement

5. Severity & SLA

CriticalCVSS 9.0+
Patch within 7 days
HighCVSS 7.0-8.9
Patch within 30 days
MediumCVSS 4.0-6.9
Patch within 90 days

6. Contact