Responsible disclosure

Found something? Tell us.

We would rather hear it from you than read about it later. This page is the whole process — there is no legal maze in front of it.

01 · How to report

Use the contact form, subject “Security disclosure.”

The contact form routes to a monitored queue. We do not publish a direct mailbox for disclosures, because an unmonitored address is worse than no address.

Do not include real personal data in your report

Not yours, not a patron’s, not a customer’s. Describe the issue, the steps, and the impact. If a proof of concept requires personal data to demonstrate, say so and we will arrange a channel — do not paste it into a form. The form itself rejects submissions that look like they contain personal or credential data.

02 · Scope

What we want to hear about.

In scope

The Laurel Secure API and portal, this website, the LaurelID Verifier application, the device-to-platform ingestion contract, and anything that would let patron identity data reach the platform.

Especially wanted

Any path that crosses the privacy boundary, defeats report suppression, allows cross-tenant reads, replays a verification event into a second counter increment, or bypasses a device lifecycle control.

Out of scope

Findings against a third-party provider’s own infrastructure, missing headers with no demonstrated impact, automated scanner output without a working scenario, and social engineering of our staff or customers.

Never in scope

Testing against a customer’s production deployment, a live venue, or real patrons. Ask us for a test environment instead — we will say yes.

03 · What we commit to

Our side of it.

  1. Acknowledge within three business days

    A human reply confirming we have it, not an autoresponder.

  2. Assess and tell you what we found

    Including if we disagree that it is a vulnerability, with our reasoning.

  3. Fix, and tell you when

    With a timeline proportional to severity, and an update if that timeline changes.

  4. Credit you, if you want it

    Named or anonymous, your choice. We run no paid bounty program today and will not imply otherwise.

Good-faith research

If you follow this page — test only against our own systems, avoid privacy violations and service disruption, and give us reasonable time before public disclosure — we will not pursue legal action over your research.