Cybersecurity information
This page is the cybersecurity information for LAVRIQ products, provided under Annex II of the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
1. Manufacturer
lavrik.tech GbR
Rheinstrasse 24
D-63303 Dreieich
Brand: LAVRIQ
- Website: www.lavriq.tech
- Contact: hello@lavriq.tech
- Security reports: security@lavriq.tech
- Legal notice: Legal Notice
2. What these products are for
LAVRIQ products are:
- cLAVRIQ (Cycling with LAVRIQ) — cycling tracking and performance monitoring.
- rLAVRIQ (Running with LAVRIQ) — running tracking and performance monitoring.
- fLAVRIQ (Fit with LAVRIQ) — fitness tracking and performance monitoring.
- bcLAVRIQ (Bike computer by LAVRIQ) — a bike computer app.
- lavriq.tech — web application for account management and related services.
These products are not medical devices and are not intended for clinical diagnosis or treatment.
A LAVRIQ cloud service processes data on behalf of these products.
3. How to identify the version
Mobile app versions are shown in the App Store or Google Play listing and in the app’s About screen. The LAVRIQ cloud service is identified automatically when you use the apps.
4. Product type
Mobile apps, the lavriq.tech website, and the LAVRIQ cloud service. Releases are distributed via the App Store, Google Play, and automatic cloud updates.
5. Conformity
lavrik.tech GbR declares that these products meet the essential cybersecurity requirements of Annex I of the Cyber Resilience Act (default category). The formal declaration of conformity is held in the technical file.
6. Known limitations
- cLAVRIQ, rLAVRIQ, and fLAVRIQ: iOS 18.2 or later (cLAVRIQ requires iOS 18.6); Android 8.0 or later.
- bcLAVRIQ: iOS 18.2 or later; Android 7.0 or later.
- Apple Watch companions: watchOS 11.0 or later.
- Wear OS companions: Wear OS on Android 11 or later.
- Strava, Withings, and Google Calendar features require an account with those services. LAVRIQ is not responsible for changes to their APIs.
- An internet connection is required to synchronise data. Offline sync is not supported.
7. Support period
September 2031. Security support (patches for critical vulnerabilities) is provided until this date for cLAVRIQ, rLAVRIQ, fLAVRIQ, bcLAVRIQ, lavriq.tech, and the LAVRIQ cloud service.
After this date, no further security patches will be issued unless support is extended and this page is updated.
8. Security updates
- Mobile apps: via the App Store (iOS) and Google Play (Android). Enable automatic updates in your device settings.
- Website and cloud service: updated by LAVRIQ. No action is required from you.
9. Report a vulnerability
Email security@lavriq.tech
We operate a coordinated disclosure process. We aim to acknowledge reports within two business days. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to fix it.