Responsible disclosure
If you have found a security problem, we want to hear about it, and we will not treat you as an adversary for telling us.
What we commit to
- We acknowledge your report within five working days.
- We tell you our assessment, including if we disagree that it is a problem.
- We keep you informed while we fix it, rather than going quiet.
- We credit you when it is resolved, if you want to be credited.
- We will not pursue legal action against you for research conducted in line with this page.
What helps
- Enough detail to reproduce it, including the URL or endpoint.
- What you expected, and what happened instead.
- Your assessment of the impact.
- Whether you have shared it anywhere else.
Please do not
- Access, modify or delete data that is not yours. If you can demonstrate a problem without touching real data, do that instead.
- Run denial-of-service or volumetric tests against any of our systems.
- Use social engineering, phishing or physical attacks against anyone connected to the company.
- Publish the details before we have had a reasonable chance to fix it. Talk to us about timing.
Scope, stated honestly
In scope: lynxsprint.com and anything we operate under it.
Out of scope: anything hosted by a third party we merely use, and findings that are purely theoretical with no demonstrable impact. Reports about missing headers on a static marketing page that carries no data are unlikely to be treated as vulnerabilities, though we are happy to be shown otherwise.
We do not run a paid bounty programme. We would rather say that plainly than let you spend time expecting one.