← All policies

Responsible Disclosure

Found a security hole? Here is how to tell us, and what we promise in return.

Last updated

This document is not finished: the business's legalName, address, jurisdiction, grievanceOfficer have not been filled in yet.

If you have found a vulnerability in Lumen, we want to hear about it, and we would rather hear about it from you than from somebody using it.

1.How to report

Email socialsprouts1@gmail.com with “Security” in the subject. Tell us what you found, how to reproduce it, and what an attacker could do with it. A short proof of concept helps more than a scanner report.

Please give us a reasonable chance to fix it before telling anyone else.

2.What we promise

  • We will acknowledge your report within 3 working days.
  • We will tell you our assessment, and whether we are fixing it, within 10 working days.
  • We will tell you when it is fixed.
  • We will not take legal action against you for research carried out in good faith under the rules below, and we will credit you if you would like us to.

We do not currently run a paid bounty programme. We will say so plainly rather than leaving you hoping.

3.The rules

  • Test only against your own account and your own projects.
  • Do not access, change or delete anybody else’s data. If you stumble into someone else’s data, stop, and tell us what you saw and how.
  • No denial of service, no load testing, no spam, no social engineering of our staff or our providers.
  • Do not use an automated scanner against the published sites of our customers — they are somebody’s business, not a target.

4.Out of scope

  • Findings that require a compromised device or a person to be tricked into pasting something into a console.
  • Missing hardening headers with no demonstrated impact.
  • Reports produced entirely by an automated tool with no analysis.
  • Content on a site built by a customer — that is theirs. Report it under the Acceptable Use Policy instead.

Something here unclear, or not matching what the product does? Tell us — a policy that does not describe the real thing is a bug.