Vulnerability disclosure policy
LaserFocused OÜ builds and runs Kommonz. We welcome reports from security researchers and anyone else who finds a vulnerability, a privacy problem or exposed data in Kommonz. This policy explains what you may test, how to report, what you can expect from us, and how we protect good-faith research.
How to report
Email security@kommonz.com. Please include:
- the affected host, URL, API endpoint or app, with the app version and device;
- clear steps to reproduce, or a proof of concept;
- what an attacker could achieve, and under what conditions;
- any personal data or other space's data you saw (describe it; do not send it);
- whether you would like to be credited, and under what name.
Write in English or Estonian. If your report is sensitive, email us first without the details and we will agree a secure way to send them. Do not send passwords, card numbers or door credentials, including your own.
In scope
- kommonz.com and www.kommonz.com, our website;
- app.kommonz.com, the Kommonz web app, including the public marketplace and space pages;
- api.kommonz.com, the Kommonz API, including the MCP connector at
/mcpand its OAuth endpoints, and the partner API; - the Kommonz iOS app and the Kommonz Android app
(
ee.laserfocused.cowork); - the older hosts cowork.laserfocused.ee (our website) and coworking.laserfocused.ee (the web app and API);
- any other
kommonz.comhost that LaserFocused operates.
Out of scope
- Services we do not operate. Hetzner, Stripe, Cloudflare, Google, Apple, Sentry, PostHog, Resend, OpenAI and the providers that spaces connect (accounting, workspace-management, event, door-access, card-terminal and email-marketing systems). Report problems in those services to the provider. If a provider's problem affects Kommonz users, tell us too.
- Physical testing. Coworking premises, doors, door readers, card terminals and other hardware at any space.
- People. Social engineering, phishing or pretexting of LaserFocused staff, space staff or members.
- Denial of service. Load, stress or volumetric testing, and anything that degrades the service for others.
- Reports without a demonstrated security impact, for example:
- missing security headers or cookie flags;
- TLS or cipher configuration;
- email-domain policy (SPF, DKIM, DMARC);
- software version disclosure;
- clickjacking on pages with no sensitive action;
- self-XSS;
- sign-out CSRF;
- rate limits on endpoints that do not handle credentials, codes or payments;
- unvalidated output from automated scanners.
- Issues that need an unusual setup, such as a rooted or jailbroken device, an outdated browser or operating system, or physical access to an unlocked device.
Rules for testing
- Use your own test space. Create one at
app.kommonz.com with the free trial, with a name that starts with
security-test, and use only accounts you create. Do not start a paid subscription or make a real payment. If you need to test payments or a feature your trial cannot reach, email us and we will set up a test space for you. - Stay out of other people's data. Do not access, change or delete data that belongs to another space or another person. If you come across it, stop, access no more than you need to show the problem, do not keep or share it, and tell us in your report what you saw. We may need that information to meet our own legal duties.
- Do not message real people. Do not use Kommonz to send emails, email campaigns, invitations, messages or notifications to anyone other than yourself.
- Keep automated testing light. Stop if you see errors, slowdowns or rate limiting, and do not try to get around rate limits.
- Do not persist. Do not install backdoors, keep access, or move from one system to another after you have shown the problem.
- No extortion. Do not demand payment or anything else in return for your report or your silence.
- Keep it confidential until it is fixed. See coordinated disclosure below.
- Follow the law. Nothing in this policy allows you to break it.
What you can expect from us
- Acknowledge your report: within 3 business days.
- Confirm whether it is valid and how severe it is: within 10 business days of acknowledging it.
- Fix a critical issue: within 7 days of confirming it.
- Fix a high-severity issue: within 30 days of confirming it.
- Fix a medium-severity issue: within 90 days of confirming it.
- Fix a low-severity issue: planned into our normal work.
- Progress updates: at least every 14 days until the issue is resolved.
These are our targets. Business days are Monday to Friday, excluding Estonian public holidays. We set severity with the CVSS v4.0 base score, adjusted for the issue's impact on the spaces that use Kommonz and their members. If a fix will take longer than the target, we explain why and agree a new timeline with you. When a fix needs a new version of the mobile apps, the target is met once we submit the version to Apple and Google. Their review time is outside our control.
We will not share your name or contact details without your permission, unless the law requires it. If a problem also affects another vendor, we may share the technical details with that vendor so it can fix it.
Coordinated disclosure
Please give us 90 days from your report before you publish anything about it. We may ask you to publish sooner if the issue is fixed and we agree, or to wait longer if a fix is under way and we explain why. If the issue is being actively exploited, we may publish our own notice before the 90 days are up and will tell you first. When you publish, please do not include personal data or details that would help someone attack Kommonz users who have not yet updated.
Safe harbour
If you make a good-faith effort to follow this policy, we consider your research authorized. This means:
- we will not take legal action against you, or report you to law enforcement, over research that follows this policy, including accidental, good-faith breaches of it;
- we waive the parts of our terms of service that would otherwise forbid that research, for that research only;
- if a third party takes legal action against you over research that followed this policy, we will make it known that you acted with our authorization.
This safe harbour covers only claims that LaserFocused OÜ controls. It does not bind other parties, such as the coworking spaces that use Kommonz, our service providers or public authorities. If you are unsure whether something is allowed, ask us at security@kommonz.com before you do it.
No paid bounty
We do not pay rewards for reports. With your permission, we are glad to thank you by name when we publish a fix.
Changes to this policy
We may update this policy. The date at the top shows the current version. Research you started under an earlier version stays covered by that version.