Vulnerability Disclosure Policy
1. Purpose and Scope
This policy explains how security vulnerabilities affecting Laica products with digital elements may be reported.
It supports compliance with Regulation (EU) 2024/2847, the Cyber Resilience Act, and applies throughout each product’s declared support period.
Applicable to LAICA smart scales connected to the LAICA Home Wellness and Fitdays+ apps.
This policy applies throughout the declared support period of the relevant product. Reports concerning products that are no longer supported may nevertheless be reviewed to determine whether any reporting or user-information obligations apply under the Cyber Resilience Act. This does not imply that a security update will be provided for products outside their support period.
2. Reporting Vulnerabilities
We value those who take the time and effort to report security vulnerabilities according to this policy. However, we do not offer monetary rewards for vulnerability disclosures. Researchers, customers, suppliers, and other stakeholders may report suspected vulnerabilities using Laica S.p.A.’s designated vulnerability reporting contact. Reports should include (mandatory data): the affected product, version, configuration, vulnerability description, reproduction steps, impact, relevant evidence, and (not mandatory data) reporter contact details. Reports should avoid personal data, customer data, production secrets, or exploit code beyond what is necessary to demonstrate the issue safely. The privacy policy can be viewed on the website www.laica.it.
If you believe you have found a security vulnerability, please submit your report to us using the following email: customerservice@laica.com
3. Safe Harbour and Researcher Expectations
LAICA S.p.A. supports good-faith security research conducted responsibly and lawfully. Researchers must avoid privacy violations, data destruction, service disruption, social engineering, physical attacks, extortion, persistence, lateral movement, and public disclosure before coordination is complete.
LAICA S.p.A. will not pursue legal action solely on the basis of good-faith security research conducted in accordance with this policy, without prejudice to applicable law and third-party rights.
4. Assessment, Remediation, and Updates
The contact person will acknowledge vulnerability reports, assign a tracking reference, preserve evidence, and assess validity, severity, affected products, exploitability, impact, mitigations, and evidence of active exploitation or severe incident. Validated vulnerabilities will be remediated without undue delay using proportionate actions such as security updates, configuration changes, mitigations, supplier fixes, or other corrective measures. Security updates will be tested, protected against tampering where applicable, and distributed through approved channels.
5. Coordinated Disclosure and CRA Reporting
LAICA S.p.A. will coordinate vulnerability disclosure, as appropriate, with the reporter and with affected suppliers and relevant authorities. Laica will keep the reporter reasonably informed during the assessment and remediation process, taking into account the complexity and sensitivity of the reported vulnerability.
Where LAICA S.p.A. becomes aware of an actively exploited vulnerability or a severe incident affecting the security of a product with digital elements, it will promptly assess the event and make any notifications required under the Cyber Resilience Act within the applicable regulatory timelines. Laica will also inform impacted users, and where appropriate all users, of the vulnerability or incident, the relevant risks and any mitigation or corrective measures they should take.
Once an appropriate security update has been made available, LAICA S.p.A. will publish information on the fixed vulnerability, including the affected products, the impact and severity of the vulnerability, and clear instructions on the actions users should take. Publication may be delayed where duly justified cybersecurity risks require users to be given sufficient time to apply the relevant update.
6. Communications, Suppliers, Records, and Review
Where third-party components are affected, LAICA S.p.A. will coordinate, as appropriate, with the relevant suppliers or maintainers. LAICA S.p.A. will document and manage vulnerability reports in accordance with its internal processes and applicable legal obligations. This policy will be reviewed periodically and following significant product, regulatory or incident-response changes. Laica will endeavour to provide reasonable status updates during the assessment and remediation process, taking into account the complexity and sensitivity of the reported vulnerability.







