Security Policy
Last updated: March 16, 2026
The security of our users and their data is our highest priority. We value the help of security researchers and the community in keeping Loek safe.
Reporting a Vulnerability
If you discover a security vulnerability in Loek, please report it responsibly. Do not open a public issue.
security[at]focusmet.nl
What to include
- Description of the vulnerability
- Steps to reproduce or proof of concept
- Affected component(s) and version(s)
- Potential impact
What to Expect
We take every report seriously and aim for a timely resolution.
Acknowledgement within 48 hours
We will confirm receipt of your report.
Assessment within 7 days
We will share an initial assessment and expected timeline.
Fix for critical issues within 30 days
We aim to resolve critical vulnerabilities as quickly as possible.
Scope
In scope
- Backend API (api.focusmetloek.nl)
- Website (focusmetloek.nl)
- Admin dashboard (dashboard.focusmetloek.nl)
- Device firmware and OTA update mechanism
- Authentication and authorization (JWT, device tokens, Somtoday OAuth)
- Payment processing (Mollie integration)
- Data storage and encryption
Out of scope
- Somtoday's own API and infrastructure
- Mollie's payment platform
- Third-party dependencies (report these to the upstream project, but let us know if they affect Loek)
- Denial of service attacks
- Social engineering
- Physical attacks against devices
Supported Versions
Older versions may not receive security patches. We recommend always running the latest version.
| Component | Supported |
|---|---|
| Backend / Website / Dashboard | Latest release |
| Firmware | Latest two minor versions |
Safe Harbor
We consider security research conducted in good faith to be authorized. We will not pursue legal action against researchers who:
- Report vulnerabilities through the channels listed above
- Avoid accessing, modifying, or deleting data belonging to other users
- Do not disrupt our services or degrade the experience for other users
- Allow reasonable time for us to address the issue before public disclosure
Coordinated Disclosure
We follow a 90-day coordinated disclosure timeline.
After reporting, we ask that you:
- Allow up to 90 days for us to develop and release a fix
- Coordinate public disclosure with us
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
We are happy to credit researchers in our release notes (unless you prefer to remain anonymous).
Found a security issue?
Contact us at security[at]focusmet.nl
For general inquiries: support[at]focusmet.nl