RESPONSIBLE DISCLOSURE
Reporting channel for vulnerabilities in Lapsor systems
We hold our own infrastructure to the same standard we apply when auditing our clients. If you find a vulnerability in our systems, write to contacto@lapsor.com.
Scope
- lapsor.com and its subdomains.
- Internet-facing services that Lapsor operates under its own name.
Rules
- Do not access third-party data. If you come across any, stop testing and tell us immediately.
- Do not degrade the service: denial of service and load testing are excluded.
- Do not use social engineering against our team or our suppliers.
- Agree a coordinated disclosure window with us before publishing the finding.
Response commitment
- Acknowledgement within 24 hours.
- Our decision on the report, accepted or rejected, with the reasons.
- Regular status updates until remediation is complete.
- Public credit at the reporter's request, once the fix is published.
How to report
Send the report to contacto@lapsor.com with reproduction steps and, if you have one, a proof of concept. If the report contains sensitive data, say so in the first email and we will open an encrypted channel.
Request a proposal with the scope defined
Tell us which assets you want tested and we will reply within 24 hours with the scope in writing.