Responsible Disclosure Policy

At Living Security, we take the security of our platform and our customers' data seriously. We welcome reports from security researchers and the broader community who identify potential vulnerabilities in our systems.


How to Report

If you believe you've discovered a security vulnerability, please send a detailed report to vulnerabilities@livingsecurity.com. To help us triage effectively, please include:

  • A clear description of the vulnerability
  • The affected URL, endpoint, or component
  • Steps to reproduce the issue
  • The potential impact as you understand it

We aim to acknowledge all reports within 5 business days and will keep you informed as we investigate.


What to Expect

We will:

  • Acknowledge receipt of your report promptly
  • Investigate the issue in good faith
  • Credit you publicly for valid, confirmed findings (if you'd like recognition)
  • Work to remediate confirmed vulnerabilities in a timely manner

We will not:

  • Pursue legal action against researchers who act in good faith and follow this policy
  • Share your personal information with third parties without your consent

Bug Bounty

Living Security does not currently operate a paid bug bounty program. We are unable to offer monetary compensation for vulnerability reports at this time.

For confirmed, valid findings, we're happy to offer public acknowledgment — including credit on this page, in release notes, or via a LinkedIn recommendation upon request.


Ground Rules

To qualify for good-faith protections under this policy, please:

  • Avoid accessing, modifying, or deleting data that isn't yours
  • Do not disrupt or degrade our services or our customers' experience
  • Do not use social engineering, phishing, or physical attacks against our team or infrastructure
  • Give us reasonable time to investigate and respond before any public disclosure
  • Do not demand payment as a condition of disclosure — we treat this as extortion, not research

Scope

This policy applies to livingsecurity.com and Living Security's core platform. Third-party services and infrastructure we do not control are out of scope.


Thank You

Security researchers help make the internet safer for everyone. We genuinely appreciate the time and effort it takes to identify and responsibly report issues. If you have questions about this policy, reach out to vulnerabilities@livingsecurity.com.

 

Last updated: May 2026



# # # # # # # # # # # #