Skip to content

Security Policy

Last updated: March 16, 2026

The security of our users and their data is our highest priority. We value the help of security researchers and the community in keeping Loek safe.

Reporting a Vulnerability

If you discover a security vulnerability in Loek, please report it responsibly. Do not open a public issue.

Email

security[at]focusmet.nl

What to include

  • Description of the vulnerability
  • Steps to reproduce or proof of concept
  • Affected component(s) and version(s)
  • Potential impact

What to Expect

We take every report seriously and aim for a timely resolution.

1

Acknowledgement within 48 hours

We will confirm receipt of your report.

2

Assessment within 7 days

We will share an initial assessment and expected timeline.

3

Fix for critical issues within 30 days

We aim to resolve critical vulnerabilities as quickly as possible.

Scope

In scope

  • Backend API (api.focusmetloek.nl)
  • Website (focusmetloek.nl)
  • Admin dashboard (dashboard.focusmetloek.nl)
  • Device firmware and OTA update mechanism
  • Authentication and authorization (JWT, device tokens, Somtoday OAuth)
  • Payment processing (Mollie integration)
  • Data storage and encryption

Out of scope

  • Somtoday's own API and infrastructure
  • Mollie's payment platform
  • Third-party dependencies (report these to the upstream project, but let us know if they affect Loek)
  • Denial of service attacks
  • Social engineering
  • Physical attacks against devices

Supported Versions

Older versions may not receive security patches. We recommend always running the latest version.

ComponentSupported
Backend / Website / DashboardLatest release
FirmwareLatest two minor versions

Safe Harbor

We consider security research conducted in good faith to be authorized. We will not pursue legal action against researchers who:

  • Report vulnerabilities through the channels listed above
  • Avoid accessing, modifying, or deleting data belonging to other users
  • Do not disrupt our services or degrade the experience for other users
  • Allow reasonable time for us to address the issue before public disclosure

Coordinated Disclosure

We follow a 90-day coordinated disclosure timeline.

After reporting, we ask that you:

  • Allow up to 90 days for us to develop and release a fix
  • Coordinate public disclosure with us
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it

We are happy to credit researchers in our release notes (unless you prefer to remain anonymous).

Found a security issue?

Contact us at security[at]focusmet.nl

For general inquiries: support[at]focusmet.nl