Responsible disclosure
If you have found a security issue in LifeWyn, we want to hear about it and we will treat you well for telling us. This page is the whole policy — there is nothing else to agree to.
Report it here
security@lifewyn.comPlease include what you found, the steps to reproduce it, and what an attacker could do with it. A short proof of concept helps more than a long description. If the report contains sensitive detail, say so and we will arrange an encrypted channel before you send it.
Our side
What we commit to
We acknowledge within 3 working days
You will get a human reply confirming we have the report and who is looking at it — not an auto-responder and then silence.
Safe harbour, if you stay within this policy
We will not pursue legal action over research conducted in good faith under the rules on this page, and we will say so in writing if you ask.
We tell you what we did
You will hear our assessment, whether we agree with the severity, and when it is fixed. If we disagree with you, we will explain why rather than going quiet.
We will not ask you to stay silent indefinitely
We ask for 90 days before public disclosure, or until a fix ships if that is sooner. If we need longer we will ask, with a reason.
In scope
- lifewyn.com and its subdomains, including the web application
- The public API served through the gateway
- The LifeWyn Android application
- The LifeWyn iOS application
Out of scope
- Denial of service, volumetric testing, or anything that degrades the service for other people
- Social engineering of our staff, our users, or our suppliers — including phishing
- Physical attacks against people or premises
- Findings from automated scanners without a demonstrated, exploitable impact
- Missing hardening headers or best-practice recommendations with no attack path attached
- Vulnerabilities in third-party services we do not control — report those to their owner
Rules of engagement
- Test only against accounts you own. Do not access, modify or retain another person's data — if you encounter it accidentally, stop, and tell us what you saw.
- Do not run anything that degrades the service. If demonstrating impact requires volume, describe the attack instead and we will reproduce it ourselves.
- Give us 90 days before publishing, or until a fix ships if that comes sooner.
- Do not use a finding as leverage. A report is not a negotiation.
What we do not offer
There is no paid bounty programme, no hall of fame and no published audit report, because none of those things exist yet. We would rather tell you that here than let you find out after doing the work. If you would like public credit for a valid report, ask and we will give it. If a bounty programme starts, this page will say so.