Skip to content

Responsible disclosure

If you have found a security problem, we want to hear about it, and we will not treat you as an adversary for telling us.

Report it to

contact@lynxsprint.com

This address is also published at /.well-known/security.txt.

What we commit to

  • We acknowledge your report within five working days.
  • We tell you our assessment, including if we disagree that it is a problem.
  • We keep you informed while we fix it, rather than going quiet.
  • We credit you when it is resolved, if you want to be credited.
  • We will not pursue legal action against you for research conducted in line with this page.

What helps

  • Enough detail to reproduce it, including the URL or endpoint.
  • What you expected, and what happened instead.
  • Your assessment of the impact.
  • Whether you have shared it anywhere else.

Please do not

  • Access, modify or delete data that is not yours. If you can demonstrate a problem without touching real data, do that instead.
  • Run denial-of-service or volumetric tests against any of our systems.
  • Use social engineering, phishing or physical attacks against anyone connected to the company.
  • Publish the details before we have had a reasonable chance to fix it. Talk to us about timing.

Scope, stated honestly

In scope: lynxsprint.com and anything we operate under it.

Out of scope: anything hosted by a third party we merely use, and findings that are purely theoretical with no demonstrable impact. Reports about missing headers on a static marketing page that carries no data are unlikely to be treated as vulnerabilities, though we are happy to be shown otherwise.

We do not run a paid bounty programme. We would rather say that plainly than let you spend time expecting one.