How to report a security issue.
This page is the public vulnerability-disclosure policy for LumenFlow Cloud. It covers how to report, what is in scope, safe-harbour expectations, and our remediation response targets.
How to report
Email security@lumenflow.cloud with a clear description of the issue, the affected surface, steps to reproduce, and any proof-of-concept that stays within the safe-harbour limits below. Do not include customer data you do not own.
Report channel: security@lumenflow.cloud
Scope
In scope
- The LumenFlow Cloud hosted control plane, APIs, authentication, and dashboard.
- Governed agent runtime surfaces we operate, including tool-dispatch and approval paths.
- Configuration and dependency issues in the systems we own where we can remediate.
Out of scope
- Social engineering of staff, physical attacks, or denial-of-service against availability.
- Findings that require access to another customer's workspace or data you do not own.
- Issues solely in third-party services we do not operate or configure.
Safe harbour
If you research and report a vulnerability in good faith, avoid privacy violations, data destruction, and service interruption, and give us a reasonable chance to remediate before public disclosure, we will not pursue legal action against you for that research and report.
Response commitment
Remediation response targets follow our Security Remediation SLA Policy. Maximum age to remediation by severity:
- Critical: 7 calendar days
- High: 14 calendar days
- Medium: 30 calendar days
- Low: 90 calendar days
This is a coordinated-disclosure policy. It does not offer payment, rewards, or a bug-bounty programme.