Vulnerability Disclosure Policy

Guidelines for reporting potential vulnerabilities in LaunchSafe-owned services safely and responsibly.

Last updated: July 2026

How to report

Email security@launchsafe.com with the affected asset, vulnerability type, reproduction steps, potential impact, and any supporting evidence. Use English and avoid including unnecessary personal data, secrets, or destructive payloads.

Scope

This policy covers security vulnerabilities in LaunchSafe-owned internet-facing services and applications. Third-party services, customer-controlled targets, social accounts, physical locations, and systems not owned by LaunchSafe are out of scope unless LaunchSafe confirms otherwise in writing.

Safe harbor

When research is conducted in good faith, follows this policy, avoids privacy violations and service disruption, and is reported promptly, LaunchSafe will not initiate legal action or refer the matter to law enforcement solely for that research. This safe harbor does not authorize activity that violates applicable law or third-party rights.

Testing rules

  • Use the minimum testing necessary to demonstrate the issue.
  • Do not access, modify, retain, or disclose another person's data.
  • Do not use denial-of-service, traffic flooding, destructive payloads, persistence, malware, social engineering, phishing, or physical intrusion.
  • Do not disrupt availability, degrade performance, or generate excessive automated traffic.
  • Do not test customer systems through LaunchSafe without the customer's written authorization.
  • Stop immediately and report the issue if sensitive data is encountered or service impact is possible.

Response targets

We aim to acknowledge a complete report within three business days and provide an initial triage update within ten business days. Remediation and disclosure timing depends on severity, affected systems, dependencies, and the safety of deploying a fix. These are response targets, not contractual service levels.

Coordinated disclosure

Please keep vulnerability details confidential until LaunchSafe confirms that remediation is complete or agrees to a disclosure date. We will work in good faith on reasonable attribution requests, but do not currently operate a paid bug-bounty program and cannot guarantee rewards.

Not covered by this policy

  • Reports that contain only automated scanner output without a reproducible security impact.
  • Missing security headers or best-practice observations without an exploitable consequence.
  • Self-XSS, clickjacking on pages without sensitive actions, or rate-limit observations without demonstrated impact.
  • Credential reports obtained from unrelated third-party breaches.
  • Product-support, billing, or availability questions that are not security vulnerabilities.