Found a hole? Tell us about it
We build security work for other people, so we hold this website to the same standard. If something here is broken, here is how to reach us and what happens next.
How to report
Email the details to the address at the bottom of this page and put the word Security in the subject line, so your report is not read as a sales enquiry. Please do not use the contact form for this: it goes to the same inbox, but email lets you attach evidence and keeps the thread in one place.
A report is easiest to act on when it carries:
- The address of the page, form or endpoint involved.
- What you did, step by step, in enough detail that we can repeat it.
- What happened, and what you expected to happen instead.
- Anything that shows the effect: a screenshot, a short recording, or the request and response.
- The browser, device or tool you used, if it only happens on one of them.
- The name you would like to be credited under, if you want credit at all.
What we ask of you
Look all you like, as long as the only account, data and submissions you touch are your own. While you are testing, please:
- Do not delete, alter or move data that is not yours.
- Do not read, copy or share anyone else's personal details. If a test puts you in front of someone else's information, stop there and describe what you saw rather than collecting more of it.
- Do not run scans heavy enough to slow the site down for other people, and no denial of service testing.
- Do not try phishing, social engineering or physical access against anyone connected with the company.
- Give us a reasonable time to fix the problem before you describe it in public.
What you can expect from us
We read every report that reaches the address below, and we reply to the address it was sent from. Our reply tells you whether we could reproduce the problem and what we plan to do about it, and we write to you again once it is fixed. If we decide not to act on something, we say so plainly and explain why, rather than leaving you without an answer.
We will not pursue legal action against anyone who reports in good faith, follows the requests above and gives us the chance to put the problem right.
Scope
This policy covers this website and the contact form on it. Two things sit outside it:
- The services this website links to or depends on, including WhatsApp, LinkedIn, Instagram, our email provider and our host. Those belong to the companies that run them, and reports about them are best sent there.
- Scanner output with no working example behind it, and settings or headers that carry no practical risk on a site of this kind. Send them if you like, but tell us what an attacker could actually do with them.
We do not pay for reports
There is no paid bug bounty here, and we would rather say that on the page than let you find out after the work is done. What we do offer is a person who reads your email, a straight answer and a fix. If you would like your name on the fix, tell us and we will credit you.
Contact
Security reports go to hello@lonelupustechnologies.com.
The same address is published for automated tools at /.well-known/security.txt.
Last updated
Ready to lead your pack?
Tell us what you want to create. We will bring the focus, the craft and the technology to make it real.