# Lumavo — security contact # # If you have found a vulnerability in Lumavo, please tell us. We would much rather # hear from you than find out later, and we will not pursue anyone who reports in # good faith under the terms below. Contact: mailto:security@lumavo.ai Expires: 2027-03-12T12:59:06Z Preferred-Languages: en Canonical: https://lumavo.ai/.well-known/security.txt Policy: https://lumavo.ai/security-policy # ── What we ask ────────────────────────────────────────────────────────────── # Report what you find, and give us a reasonable chance to fix it before making it # public. We aim to acknowledge within two business days. # # Please do NOT, while testing: # - access, modify, or retain data belonging to anyone other than yourself # - run automated scans heavy enough to degrade the service for customers # - use social engineering, phishing, or physical access against our staff or users # # Use a test account you created. If you believe demonstrating impact requires touching # another account, stop and describe it to us instead — a clear write-up is worth more # to us than a proof of concept, and it keeps you on the right side of the line. # # ── What we will do ────────────────────────────────────────────────────────── # Acknowledge your report, keep you updated while we fix it, and credit you if you # would like to be credited. We are a small company and do not currently pay bounties; # we would rather say that plainly than imply one.