lumenify.xyz / private disclosure infrastructure
The operating system for defensible security decisions.
Lumenify brings structure to private vulnerability disclosure: evidence-driven intake, expert triage, duplicate analysis, and accountable closure decisions.
Reports should be judged by technical correctness, reproducibility, impact, and evidence quality, not reputation or politics.
Accounting path accepts stale vault share state
the gap
Security decisions are fragmented. Context gets lost.
Reports arrive through email, Discord, forms, DMs, and bounty platforms. Triage decisions become inconsistent, duplicate reasoning is hard to defend, and critical context disappears across conversations.
What protocols experience
demand sideapproach
Vulnerability disclosure should operate like an investigation.
Lumenify is not an open bounty marketplace. It is the operating layer for private vulnerability intake, evidence review, triage accountability, and defensible security decisions.
Evidence over reputation
Reports are evaluated by technical correctness, reproducibility, impact, and evidence quality.
Structure without walls
Low-signal reports fail evidence checks, but unknown researchers are not excluded when the work is solid.
Technical closure reasons required
A report cannot be closed with a label alone. Closure requires a technical explanation.
Duplicates require same-fix sufficiency
Duplicate means same root cause, same affected path, same impact, and one fix resolves both.
operations
Structured vulnerability operations, not another inbox.
Lumenify turns disclosure into a managed workflow: complete report packets, evidence-based triage, duplicate analysis, and accountable closure records.
Every decision starts from a structured evidence packet.
Protocol teams need more than a status label. They need to know what was submitted, how it was reviewed, why it was accepted or closed, and which evidence supports the decision.
Affected asset, root cause, attack path, PoC, and supporting references are captured up front.
Review maps evidence to scope, exploitability, severity, duplicate status, and protocol action.
Accepted, duplicate, out-of-scope, or rejected outcomes require rationale and references.
Evidence quality gate
intakeIncomplete reports are identified before they become protocol-facing work.
Duplicate analysis
closureDuplicate means same root cause, same affected path, and a same-fix conclusion.
Rationale required
decisionsAccepted, duplicate, out-of-scope, and rejected decisions require a written reason.
Protocol visibility
operationsTeams see ownership, status, quality-gate outcomes, and response-time pressure in one workspace.
product
Private intake. Expert triage. Accountable resolution.
Lumenify is a private disclosure room with real operational controls: report evidence, triage judgment, project response, accountability, and structured decisions.
Accounting path accepts stale vault share state
PoC attached. The freeze reproduces after the last withdrawer exits and the first new depositor re-enters.
Scope mapped to vault accounting. Evidence packet validated; protocol review opened with triage notes.
Private report submission
intakeGuided fields for target, scope, root cause, impact, reproduction, and PoC attachments.
Project + researcher thread
privateOne report, one private record, one shared timeline. No public issue leakage.
Expert triage notes
reviewExpert triage maps evidence to exploitability, affected path, severity, and duplicate status.
Structured closure forms
rulesA decision cannot close without rationale, citations, and impact reasoning.
Illustrative SLA dashboard
metricsIllustrative quality signals
qualityreport intake
A structured path before a private thread exists.
Lumenify submissions are not free-form emails. A report becomes a reviewable investigation packet before a protocol ever has to spend engineering time on it.
Program lock
The researcher selects an active program and confirms the name before sensitive details can be submitted.
Scope + impact map
Affected asset, asset type, impact category, severity claim, and out-of-scope warnings are captured up front.
Evidence workspace
Title, root cause, reproduction steps, PoC, references, and private attachments are grouped into one review packet.
Quality gate
Completeness, evidence quality, exploitability, and duplicate similarity are checked before escalation.
Review-ready packet
The final screen summarizes every claim, attestation, affected asset path, and evidence field before the private thread opens.
Program confirmation required before continuing.
- Program confirmed before intake
- In-scope asset selected
- Impact mapped to severity
- Runnable PoC or exact reproduction attached
- Researcher attestation recorded
for protocols
Less noise. Better decisions.
Lumenify filters noise without blocking talent. Protocols get private intake, expert triage, clear severity mapping, duplicate review, and response-time accountability.
Join the protocol pilotfor researchers
Let the evidence carry the report.
Lumenify is built for researchers who can explain what is wrong, why it matters, and how it can be reproduced. The report is judged on the work.
Apply as researcherworkflow
From report to resolution.
Every status is operational. Each transition records what changed, who owns the next step, and which evidence is required.
Submitted
Researcher provides affected asset, root cause, impact claim, reproduction steps, and PoC evidence.
Evidence: asset + PoC + impactQuality Gate
Completeness checks confirm asset, root cause, attack path, PoC, and evidence before escalation.
Evidence: scope + evidenceEscalated
Complete reports are escalated to the protocol with a structured packet and Lumenify review rationale.
Evidence: packet + rationaleRejected
Incomplete reports are rejected at the quality gate with a concrete reason. Signal-bond enforcement is planned pilot economics.
Evidence: reason + missing proofProtocol Review
Protocol teams review escalated reports and provide validity, duplicate, scope, or impact decisions.
Evidence: protocol decisionValidated
The report is reproducible or technically accepted as a valid vulnerability candidate.
Evidence: root cause + impactAccepted / Closed
Every final decision carries a structured closure reason, duplicate analysis, or scope citation.
Evidence: reason + referencesResolved
Resolution tracks fix references, disclosure status, and post-fix verification when applicable.
Evidence: fix + verificationprinciples
Security decisions need accountability.
Duplicate, out-of-scope, informational, rejected, accepted, and severity-downgraded are not one-word outcomes. They are decisions that need rationale.
Accepted, reproducible security work gets a clear technical record.
Reports need scoped assets, root cause, reproduction steps, impact, and supporting proof.
Must cite the exact written scope clause.
Must cite prior report hash or internal ID and same-fix analysis.
No closure solely because a report looks AI-written. Hallucinated or non-reproducible reports are rejected on evidence.
Must explain the impact delta and map to the project-specific severity overlay.
quality signals
Trust is earned through outcomes.
Lumenify does not ask protocols to rely on badges blindly. Trust comes from complete packets, reproducible reports, accurate severity calls, and professional disclosure behavior.
Unknown signal
The first report is judged on evidence quality, not name recognition.
Complete packets
Reports include scoped assets, reproduction steps, PoC evidence, and clear impact claims.
Reproducible work
Prior submissions have been technically reproducible or accepted by protocol teams.
Consistent outcomes
Trust improves when prior work is reproducible, correctly scoped, and useful to protocol teams.
Expert reviewer
Invited triage, mediation, and quality review opportunities for proven specialists.
workflow fit
Why disclosure needs purpose-built operations.
Security reports are not ordinary support tickets. They need evidence quality, exploitability review, duplicate logic, and defensible closure records.
Shared inbox
unstructuredReports arrive with uneven evidence, unclear ownership, missing context, and no durable closure trail.
Generic ticket queue
too broadTickets track status, but they do not enforce exploitability, duplicate analysis, severity mapping, or researcher-facing rationale.
Lumenify vulnerability operations
purpose-builtIntake, triage, duplicate review, closure rationale, and disclosure decisions live in one structured workflow.
faq
Workflow questions, answered.
The policy is simple: serious vulnerability reports deserve structured review, and protocol teams need defensible decisions.
Is Lumenify a bug bounty marketplace?
No. Lumenify does not exist to help researchers find bounties or to run another public bounty marketplace. It exists to structure private vulnerability disclosure, triage, and security decision-making.
How does Lumenify reduce noisy submissions?
The intake workflow requires scope, affected asset, root cause, attack path, PoC, impact, and evidence before a report becomes a protocol-facing packet.
What happens when a report is a duplicate?
Duplicate closure requires the prior report reference, same-root-cause analysis, same affected path, and whether the same fix resolves both reports.
Who owns triage decisions?
Lumenify structures the evidence and rationale. Protocol teams keep final ownership of program scope and remediation decisions.
How are researchers treated fairly?
Researchers get clear requirements and technical closure reasons instead of unexplained labels. Rebuttal windows are reserved for disputed protocol decisions, not incomplete first-pass reports.
What is validated during the pilot?
The pilot validates intake quality, triage workflow, duplicate handling, closure rationale, and protocol response visibility before deeper automation.
private pilot
Launching invite-only.
We are onboarding a small group of EVM DeFi protocols and evidence-driven researchers for the first private pilot.
3-5
pilot protocolsMid-sized EVM DeFi teams with active engineering and real vulnerability intake needs.
5-10
selected researchersPseudonymous participation allowed. Quality signals start from evidence, PoCs, vouching, and validated outcomes.
EVM DeFi
first ecosystemVaults, lending, staking, bridges, perps, and asset-management protocols first.
Private workflow
pilot boundaryThe pilot focuses on intake, triage, duplicate handling, closure rationale, and protocol response visibility.
Join the protocol pilot
Request access in one step.
Apply as researcher
Apply in one step. Do not include live vulnerability details.
lumenify.xyz