Lemonlime Vulnerability Disclosure
LemonLime publishes no /.well-known/security.txt (404 on the canonical apex host), but its public security page does carry a stated responsible-disclosure posture and a dedicated security contact address. There is no bug bounty program and no HackerOne/Bugcrowd/Intigriti listing — disclosure is direct-to-vendor by email. The mechanical probe (0-working/probe-security-programs.py) independently confirmed this page as a disclosure hit; this file is the richer searched capture and is kept in preference to the probe's keyword-level output.
LemonLime runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.