Skip to content

RESPONSIBLE DISCLOSURE

Reporting channel for vulnerabilities in Lapsor systems

We hold our own infrastructure to the same standard we apply when auditing our clients. If you find a vulnerability in our systems, write to contacto@lapsor.com.

Scope

  • lapsor.com and its subdomains.
  • Internet-facing services that Lapsor operates under its own name.

Rules

  • Do not access third-party data. If you come across any, stop testing and tell us immediately.
  • Do not degrade the service: denial of service and load testing are excluded.
  • Do not use social engineering against our team or our suppliers.
  • Agree a coordinated disclosure window with us before publishing the finding.

Response commitment

  • Acknowledgement within 24 hours.
  • Our decision on the report, accepted or rejected, with the reasons.
  • Regular status updates until remediation is complete.
  • Public credit at the reporter's request, once the fix is published.

How to report

Send the report to contacto@lapsor.com with reproduction steps and, if you have one, a proof of concept. If the report contains sensitive data, say so in the first email and we will open an encrypted channel.

Request a proposal with the scope defined

Tell us which assets you want tested and we will reply within 24 hours with the scope in writing.

Request an auditCall