Report a vulnerability
If you find a vulnerability in the Lysena website or app, thank you: please report it to us before making it public. This page explains how, and what we do in return.
In scope
- The website and the beta sign-up form.
- The Lysena app for Android and iOS, once available, and the servers it uses: model catalog, lists of dangerous websites, accounts.
Out of scope: attacks that take the service down (DoS), spam, scams or social engineering against us or our users, and issues in third-party services we do not run.
How to report
Write to the address below and include:
- where the issue is (page, app version, phone model);
- the steps to reproduce it;
- what an attacker could achieve with it.
If the issue exposes other people’s data, stop as soon as you have confirmed it and do not keep that data.
What we do
- We confirm we received your report within 5 working days.
- We keep you updated on what we have verified and when the fix will ship.
- We fix serious vulnerabilities as soon as possible, usually within 90 days.
- If you wish, we thank you by name once the fix is out. We do not offer cash rewards at the moment.
What we ask of you
- Do not make the issue public before it is fixed, or before 90 days from your report unless we agree otherwise.
- Do not access, change or delete other people’s data.
- Do not slow down the service and do not run large-scale automated attacks.
If you report in good faith and follow these rules, we will not take legal action against you.