Security
Report anything. We will not send lawyers.
A company whose entire argument is that its architecture holds should want people trying to break it. If something here does not hold, we would rather hear it from you than read it in someone else’s story.
Coordinated disclosure
Where to send it, and what happens next.
Include what you found and how to reproduce it. A human reads it, not a queue.
Safe harbour
We commit to not pursuing legal action against good faith research. Good faith means testing hardware and accounts that are yours, not reaching other people’s data, not degrading the service for anyone else, and giving us a reasonable window before you publish. Stay inside that and you have our word in writing on this page, versioned, where you can point at it later.
If you are unsure whether something is inside the line, ask first. Asking is never held against you.
Scope
What is fair game, stated plainly.
- In scope, today
- homehover.com and the waitlist API. That is the entire attack surface right now, and it is small on purpose
- In scope, once hardware ships
- The dock and the aircraft you own, the firmware on them, and the app paired to them
- Out of scope
- Anyone else’s device, dock or account. Volumetric and denial of service testing. Social engineering of a person. Physical entry anywhere
Threat model
The threats we design against, hardest first.
| Rank | Threat | What it is | What blunts it |
|---|---|---|---|
| 01 | Us, in five years | A later version of this company under financial pressure, or a new owner after an acquisition. | Keys are derived on your hardware and never sent to us, so a future us has nothing to hand over. |
| 02 | Compelled disclosure | A subpoena, a warrant, or a national security letter served on us. | We can produce ciphertext and device health. We cannot produce anything readable. |
| 03 | Compromise of our infrastructure | An attacker with our credentials, inside our systems. | They reach device telemetry and a waitlist table. Footage is not there to reach. |
| 04 | Compromise of a customer dock | The serious one. A dock is a computer sitting on a home network. | Signed firmware, and a geofence enforced below the level a compromised dock can reach. |
| 05 | Aircraft theft | Someone lifts the aircraft off the dock. | It cannot be paired to another dock, and it carries no readable recordings. |
Rank 01 is first because it is the threat a security company is least likely to publish and the one a customer can do least about. Every other row is downstream of getting that one right. The full reasoning is on the architecture page.
What is not done yet
There is no shipping hardware, so there has been no third party audit. We have committed to commissioning one before the first unit ships, and to publishing the report here whether or not it is flattering. Until that report exists, everything on this page is a design intention rather than an audited fact, and you should read it that way.
There is also no bug bounty, because there is not yet a product to find bugs in. When the first firmware ships, the bounty and its numbers get published on this page, not announced and then quietly scoped down.
Early access
Luna ships to the first 500 homes.
Join the list and you take a position. Refer someone and you move up it. No deposit, no card, and we will not sell your address any more than we would sell your footage.
Check your email
Your position is assigned the moment you confirm. Unconfirmed addresses do not hold a place, which is why the number on this page means something.