1. Purpose
LumiTalk welcomes good-faith reports that help protect its public systems and users. This policy describes authorized research boundaries; it is not a bug-bounty program, promise of payment, waiver for unlawful conduct, or authorization to test customer systems.
2. In-scope systems
Testing is limited to publicly accessible LumiTalk-owned web properties unless written authorization expressly identifies another asset. Third-party services, customer environments, social-engineering targets, physical facilities, and unrelated domains are out of scope.
3. Good-faith requirements
- Make a reasonable effort to avoid privacy violations, data access, disruption, degradation, and harm.
- Use the minimum testing necessary to demonstrate the issue.
- Stop immediately if you encounter personal information, Customer Data, credentials, or non-public records.
- Do not retain, copy, alter, delete, or disclose accessed information.
- Allow reasonable time for investigation and remediation before public disclosure.
4. Prohibited testing
- Denial of service, high-volume automated scanning, traffic flooding, or resource exhaustion.
- Social engineering, phishing, credential stuffing, password spraying, or attacks on personnel or customers.
- Malware, ransomware, destructive payloads, persistence, or lateral movement.
- Physical attacks, extortion, threats, or demands for payment.
- Testing third-party or customer systems without their written authorization.
5. How to report
Use the LumiTalk contact page, identify the message as a security vulnerability report, and request a secure follow-up channel before sending exploit code or sensitive evidence.
- Describe the affected URL or asset and observed behavior.
- Provide reproducible steps using non-sensitive test data.
- Explain likely impact and any conditions required.
- Include a safe method and time window for follow-up.
6. Response process
LumiTalk will review reports in good faith and prioritize based on reproducibility, impact, exploitability, and affected data or service. No specific acknowledgment, remediation, or disclosure deadline is promised by this public policy.
7. Good-faith treatment
When research complies with this policy, LumiTalk will treat it as authorized for the limited purpose of security testing and will not knowingly initiate legal action solely for that compliant research. This statement does not bind third parties, regulators, or law enforcement and does not protect violations of law or this policy.
8. Coordinated disclosure
Do not publicly disclose a vulnerability, affected customer, exploit, or non-public technical detail until LumiTalk confirms remediation or provides written consent. Any recognition or researcher credit requires mutual agreement.
9. Rewards
LumiTalk does not promise monetary rewards. Any discretionary recognition must be agreed in writing and does not create a continuing program or entitlement.





