LemFi · Vulnerability Disclosure

Lemfi Vulnerability Disclosure

Vulnerability disclosure

LemFi publishes a vulnerability disclosure policy for reporting security issues.

CompanyFinancial-ServicesFintechPaymentsRemittancesCross-Border PaymentsMoney TransferConsumer FinanceMobile BankingeSIM
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

lemfi-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-25'
method: searched
source: https://lemfi.com/en-us/legal/vulnerability-disclosure-policy
policy_url: https://lemfi.com/en-us/legal/vulnerability-disclosure-policy
policy_http_status: 200
program:
  type: vulnerability-disclosure-program
  managed_by: Inspectiv
  submission_url: https://client.inspectiv.com/vdp/lemfi/submit-report
  submission_issue_contact: programs@inspectiv.com
  bug_bounty: false
  bug_bounty_note: >-
    LemFi's policy states plainly that VDP submissions are not eligible for bounty
    payment from Inspectiv. Inspectiv runs separate paid bug bounty programs at
    https://app.inspectiv.com/, but LemFi's published program is disclosure-only.
safe_harbor: true
safe_harbor_note: >-
  Good-faith research complying with the policy is treated as "Authorized research"
  under anti-hacking and anti-circumvention laws, and LemFi commits not to initiate
  legal action for accidental, good-faith violations.
disclosure_window_days: 90
disclosure_window_note: Minimum 90-day window before public announcement.
scope:
  in_scope:
  - lemfi.com
  - LemFi Android mobile application
  - LemFi iOS mobile application
  - app.lemonade.finance
  out_of_scope:
  - Third-party systems and services
  - Test / staging environments
  - Corporate IT infrastructure
  excluded_issue_classes:
  - Social engineering
  - Denial of service
  - Theoretical vulnerabilities without a proof of concept
response_commitments:
- Respond promptly to reports
- Keep reporting researchers informed of progress
- Remediate confirmed vulnerabilities in a timely manner
- Provide a minimum 90-day disclosure window
security_txt:
  present: false
  probed:
  - url: https://lemfi.com/.well-known/security.txt
    status: 404
  note: >-
    No RFC 9116 security.txt is served. The disclosure policy exists only as an HTML
    page linked from the site footer, so an automated scanner following the well-known
    convention will not find it.
notes: >-
  LemFi ships no public API, but it does run a real, named, third-party-managed
  vulnerability disclosure program with safe harbour and a stated disclosure window —
  one of only two machine-adjacent trust surfaces this provider publishes.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lemfi-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.