Responsible disclosure

    Found a vulnerability? Tell us — we will respond within a business day.

    LemRank welcomes coordinated reports from independent security researchers. This page is the contract: what is in scope, how fast we respond, and the safe-harbour rules that protect you while you test.

    In scope

    • app.lemrank.com and lemrank.com (production web app and marketing site)
    • api.lemrank.com (public REST API)
    • LemRank Lens browser extension (Chrome MV3)
    • Edge functions hosted under the *.functions.supabase.co domain we operate

    Out of scope

    • Denial-of-service or volumetric attacks against any property.
    • Findings in third-party services we do not operate (raise those with the vendor directly).
    • Social engineering of LemRank staff, customers, or vendors.
    • Reports from automated scanners with no demonstrated impact.
    • Missing security headers without a working exploit.
    • Self-XSS or issues that require an already-compromised browser.

    Our SLAs

    • Acknowledgement
      Within 1 business day of receipt.
    • Triage and severity
      Within 3 business days.
    • Remediation target
      Critical: 7 days · High: 30 days · Medium: 60 days · Low: best effort.
    • Public credit
      On request, after the fix ships, on the researchers page.

    Safe-harbour rules

    We will not pursue legal action against researchers who act in good faith and follow these rules:

    • Do not access, modify, or exfiltrate data that is not your own.
    • Use only test accounts you create for the purpose of the test.
    • Stop and report as soon as you confirm a vulnerability — do not pivot.
    • Do not publicly disclose a finding before we have shipped a fix or 90 days have passed (whichever is sooner).
    • Comply with all applicable laws in the jurisdiction you are testing from.

    How to report

    Email security@lemrank.com with:

    • A clear description of the issue and its impact.
    • Reproduction steps, including any test accounts or payloads.
    • The affected URL or endpoint.
    • Your name or handle for public credit (optional).

    For sensitive reports, request our PGP key in your first message and we will send it before you transmit details.

    Looking for our security controls? Read the security overview.