Vulnerability Disclosure Policy
How to report a security issue in LaunchSafe, what is in scope, our response commitments, and the safe-harbor terms for good-faith research.
We want to hear about security issues in LaunchSafe. This policy explains how to report one, what we will do, and the protection we offer for good-faith research.
How to report
Email hello@launchsafe.com with "Security" in the subject, or use the address in our security.txt. Please include:
- Where the issue is: the URL, endpoint or product component.
- What the impact is, and the steps to reproduce it.
- Any proof of concept, logs or screenshots that help us confirm it.
- How you would like to be credited, if at all.
Report in English where you can. We accept anonymous reports.
What we commit to
- We acknowledge your report within 2 business days.
- We give an initial assessment, including our severity view, within 5 business days.
- We update you at least every 10 business days until the issue is closed.
- We aim to remediate critical issues within 7 days, high within 30 days, and the rest on our normal release schedule.
- We credit you publicly when we ship the fix, if you want that.
We do not currently run a paid bug-bounty programme. If that changes we will say so here.
In scope
- launchsafe.com and its subdomains.
- The LaunchSafe platform, API and agents.
- Our official client libraries and packages.
Out of scope
- Denial-of-service, volumetric or resource-exhaustion testing.
- Social engineering of our staff, customers or suppliers, and physical attacks.
- Automated scanner output with no demonstrated impact.
- Missing best-practice headers, cookie flags or TLS configuration with no exploitable consequence.
- Issues that need a rooted device, a stolen credential or an already-compromised machine to work.
- Reports about third-party services we use. Take those to the provider.
Rules for testing
- Test only against your own accounts and data. Do not access, modify or delete anyone else's.
- Stop as soon as you have confirmed a vulnerability, and take only what you need to demonstrate it.
- Do not degrade the service for others.
- Do not publish before we have fixed the issue and agreed a date with you.
Safe harbour
If you follow this policy in good faith we will treat your research as authorised access. We will not pursue civil action or refer you to law enforcement, we will not treat it as a breach of our Acceptable Use Policy, and if a third party brings a claim against you for that research we will make it known that you were acting within this policy. This is not a waiver of anyone else's rights, and it does not authorise you to test systems belonging to our customers or suppliers.
Coordinated disclosure
We work to a 90-day disclosure window from the date you report. If we need longer we will explain why and agree an extension with you. Where an issue affects customers we publish an advisory once a fix is available.