Disclosure policy
Coordinated disclosure, evidence first.
Lumenify exists to make private vulnerability disclosure more serious, reproducible, and fair. This policy applies to reports about Lumenify-operated systems and to reports submitted through Lumenify pilot programs.
Reporting To Lumenify
Vulnerability reports are submitted through Lumenify's structured web intake, not by email. The report flow requires scoped asset details, impact, reproduction steps, proof of concept evidence, and researcher attestations before review. Do not publicly disclose an unresolved issue before we have had a reasonable chance to investigate.
Structured Intake Steps
- Select the active program and confirm the intended recipient before sensitive details are accepted.
- Map the report to an in-scope asset, affected path, impact category, and severity claim.
- Provide a clear title, root-cause explanation, reproduction steps, impact details, references, and proof of concept evidence.
- Attach supporting material only when it helps reproduce or validate the issue.
- Review the final packet, confirm the required attestations, and submit into the private report thread.
Researcher Expectations
- Submit only scoped, good-faith security research.
- Include enough detail for a technical reviewer to reproduce or evaluate the claim.
- Do not access, modify, exfiltrate, or destroy third-party data.
- Do not perform denial-of-service, spam, phishing, social engineering, or physical attacks.
- Do not test third-party protocols through Lumenify unless the program has explicitly authorized that testing.
Triage Standards
Reports are evaluated by scope, reproducibility, exploitability, root cause, affected path, and practical impact. Rejections, duplicate decisions, and severity downgrades should include technical reasoning rather than unexplained labels.
Safe Harbor Intent
Lumenify supports good-faith research that follows written scope, avoids harm, and gives affected teams time to investigate. This policy is not legal advice and does not authorize testing against third-party assets outside an active program's written scope.