Vulnerability disclosure
We welcome reports from security researchers. Here's how to reach us and what you can expect in return.
Report an issueReporting a vulnerability
If you believe you've found a security vulnerability in our website or products, please email lazlosoftwaresolution@gmail.com. Include enough detail for us to reproduce it — the affected URL or component, steps to reproduce, and any proof-of-concept — and we'll take it from there.
A machine-readable contact record is published at /.well-known/security.txt (RFC 9116).
What to expect
- We aim to acknowledge your report promptly and keep you updated as we investigate.
- We'll work to validate and remediate confirmed issues based on severity and impact.
- We're happy to credit researchers who report responsibly, if you'd like.
Please do
- Give us a reasonable window to investigate and fix before any public disclosure.
- Only test against your own accounts or data, and avoid actions that could harm others.
- Stop at the point of demonstrating a vulnerability — don't access, modify, or exfiltrate data.
Please don't
- Run denial-of-service tests, spam, or social-engineering against our staff or customers.
- Access, download, or destroy data that isn't yours.
- Publicly disclose an issue before we've had a chance to address it.
Scope
This policy covers our public website and the products we operate. Third-party services we rely on are governed by their own disclosure programmes. When in doubt, email us and ask.
For our broader security practices, data handling, and compliance posture, see our Trust Center.