Security

Responsible disclosure.

Help us improve Lexyte while protecting users and avoiding unnecessary harm.

01

Report privately

Email security@lexyte.example with affected version, environment, impact, reproduction steps, and a minimal proof. Encrypt sensitive material using the public key published at /.well-known/security.txt.

02

Safe-harbor expectations

Act in good faith, test only systems and licenses you own or are authorized to use, minimize data access, stop when personal data appears, and allow reasonable remediation time. Do not disrupt fulfillment, degrade protections for customers, phish, extort, or publicly disclose an unpatched issue.

03

Our response

We acknowledge reports within three business days, triage severity, maintain a communication channel, and aim to provide a remediation plan within ten business days. Timelines depend on complexity and exploitation risk.

04

Scope priorities

Definition or update signature bypass, license forgery with security impact, pipe-command spoofing, protected-uninstall bypass, privilege escalation, firewall manipulation, webhook replay, expiring-link bypass, and sensitive-data logging are priority areas.