Security at LaunchSafe
Published practices for reporting vulnerabilities, handling customer data, and using an offensive-security platform responsibly.
Last updated: July 2026
Security contact
Report a suspected vulnerability privately to security@launchsafe.com. Please follow our Vulnerability Disclosure Policy.
Authorized testing
LaunchSafe is intended only for systems the customer owns or has written authorization to test. Customers define scope and rules of engagement and remain responsible for ensuring that every submitted target is authorized.
- Do not submit third-party systems without written authorization.
- Use dedicated test accounts and non-production data where possible.
- Stop testing and notify the appropriate owner if unexpected impact or third-party data exposure occurs.
- Review the complete Acceptable Use Policy.
Customer data and model use
LaunchSafe processes customer-provided scope, source code, credentials, application responses, findings, and reports to deliver the service. Customer source code and findings are not used to train shared or third-party models.
Retention and deletion
Pro scan reports are retained for 90 days. Teams and Enterprise retention follows the applicable plan or contract. Customers may contact support to request earlier deletion, subject to legal, security, and billing obligations. Contractual deletion terms are described in the Data Processing Addendum.
Service providers
LaunchSafe uses service providers to operate the platform. The current public list and processing purposes are maintained in the Data Processing Addendum. Customer data may be processed by applicable providers when required to deliver configured features.
Vulnerability management
Security reports are triaged based on reproducibility, potential impact, exploitability, and affected scope. LaunchSafe coordinates remediation and disclosure with reporters and affected parties when appropriate. Response targets are described in the Vulnerability Disclosure Policy and may vary with severity and complexity.
Incidents and availability
Operational notices are published through the LaunchSafe status page when appropriate. Customers should report suspected account or data incidents to security@launchsafe.com.
About this page
This page summarizes published practices and customer responsibilities. It is not an audit report, certification, warranty, or substitute for contractual terms. Where a contract or Data Processing Addendum applies, that document controls.