RESPONSIBLE DISCLOSURE
Help us protect the evidence desk.
We welcome good faith reports of security vulnerabilities that could affect Lumenode users, provider credentials, account data, or report integrity.
What to include
- A clear description of the issue and its security impact
- Reproduction steps or a minimal proof of concept
- The affected URL, feature, or package version
- Relevant timestamps, request identifiers, and screenshots with secrets removed
- Your preferred contact method
Safe testing rules
- Test only accounts and data you own or have permission to use
- Do not access, alter, delete, or export another user's data
- Do not perform denial of service, spam, social engineering, or physical attacks
- Do not publish the issue before we have had a reasonable opportunity to investigate
- Do not include private keys, passwords, tokens, or unnecessary personal information
Contact
Send reports through the security contact configured by the operator before launch. Until that address is published, use the Contact page and select Security. Please do not send secrets through a normal support message.
We will acknowledge valid reports, investigate in good faith, and coordinate disclosure where practical. We do not promise a reward, a specific response time, or a finding of eligibility.