Langdock · Vulnerability Disclosure

Langdock Vulnerability Disclosure

Vulnerability disclosure

Langdock publishes a Vulnerability Disclosure Policy with a scoped bug bounty program, explicit safe-harbor terms, and committed response timelines. There is no /.well-known/security.txt on any Langdock host (all probed hosts returned 404), so the policy page and the security@ mailbox are the disclosure surface.

Langdock publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyArtificial IntelligenceEnterprise AILLMAgentsModel Context ProtocolWorkflowsKnowledge ManagementGermanyEurope
Program:

Disclosure Policy

Policy

Security Contact

Contact
security@langdock.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: false
source: https://www.langdock.com/vulnerability-disclosure-policy
description: >-
  Langdock publishes a Vulnerability Disclosure Policy with a scoped bug bounty
  program, explicit safe-harbor terms, and committed response timelines. There is
  no /.well-known/security.txt on any Langdock host (all probed hosts returned 404),
  so the policy page and the security@ mailbox are the disclosure surface.
policy:
- https://www.langdock.com/vulnerability-disclosure-policy
contact:
- security@langdock.com
bug_bounty:
  program: Langdock Vulnerability Disclosure Policy (self-hosted, not on a platform)
  platform: null
  monetary_rewards: true
  reward_categories:
  - Remote Code Execution (RCE)
  - Cross Site Scripting (XSS)
  - Server-Side Request Forgery (SSRF)
  - SQL Injection (SQLi)
  - Insecure Direct Object References (IDOR)
  - Authentication bypass
  - Privilege escalation
  - Severe information or PII disclosure
  non_monetary: Other valid in-scope reports may receive mentions or Langdock swag.
  excluded_from_reward: >-
    Low-quality, low-impact, or informational issues (missing security headers,
    weak TLS ciphers, version disclosures). Duplicates — only the first valid
    report is eligible. Bounty amounts are not negotiated.
scope:
  in_scope:
  - Langdock Platform (app.langdock.com)
  out_of_scope:
  - Marketing website (www.langdock.com)
  - Mobile applications
  - Third-party dependencies or systems owned by other entities
  - Physical security, social engineering, phishing, spam, brute-force attacks
  - Denial-of-Service (DoS), distributed DoS (DDoS), or resource exhaustion attacks
  - Automated scanning or fuzzing that degrades service
safe_harbor:
  offered: true
  terms: >-
    Researchers acting in good faith, following the policy, and avoiding privacy
    violations, service disruption, or data destruction are protected from legal
    action by Langdock. All information provided is kept confidential.
response_timelines:
  acknowledgement: within 3 business days
  progress_updates: at least every 10 business days until resolution
  post_resolution: >-
    Upon validation and mitigation, Langdock alerts affected customers and may
    issue a security advisory.
reporting_requirements:
- Detailed summary and attack surface (URL and parameters)
- Potential weakness and tools used
- Proof of concept with clear, reproducible steps
- Severity level (CVSS 3.1 or low/medium/high/critical)
- Any plans for public disclosure
security_txt:
  present: false
  probed:
  - path: https://www.langdock.com/.well-known/security.txt
    status: 404
  - path: https://api.langdock.com/.well-known/security.txt
    status: 404
  - path: https://docs.langdock.com/.well-known/security.txt
    status: 404
evidence:
- source: https://www.langdock.com/vulnerability-disclosure-policy
  kind: disclosure-policy-page
  keywords:
  - bug bounty
  - responsible disclosure
  - safe harbor
  - security@langdock.com
related:
  trust_center: security/langdock-trust-center.yml
  security_overview: https://www.langdock.com/security