Report privately
Email security@lexyte.example with affected version, environment, impact, reproduction steps, and a minimal proof. Encrypt sensitive material using the public key published at /.well-known/security.txt.
Safe-harbor expectations
Act in good faith, test only systems and licenses you own or are authorized to use, minimize data access, stop when personal data appears, and allow reasonable remediation time. Do not disrupt fulfillment, degrade protections for customers, phish, extort, or publicly disclose an unpatched issue.
Our response
We acknowledge reports within three business days, triage severity, maintain a communication channel, and aim to provide a remediation plan within ten business days. Timelines depend on complexity and exploitation risk.
Scope priorities
Definition or update signature bypass, license forgery with security impact, pipe-command spoofing, protected-uninstall bypass, privilege escalation, firewall manipulation, webhook replay, expiring-link bypass, and sensitive-data logging are priority areas.