LemonLime · Vulnerability Disclosure

Lemonlime Vulnerability Disclosure

Vulnerability disclosure

LemonLime publishes no /.well-known/security.txt (404 on the canonical apex host), but its public security page does carry a stated responsible-disclosure posture and a dedicated security contact address. There is no bug bounty program and no HackerOne/Bugcrowd/Intigriti listing — disclosure is direct-to-vendor by email. The mechanical probe (0-working/probe-security-programs.py) independently confirmed this page as a disclosure hit; this file is the richer searched capture and is kept in preference to the probe's keyword-level output.

LemonLime runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyArtificial IntelligenceKnowledge ManagementAI AgentsWorkflow AutomationModel Context ProtocolEnterprise SoftwareSaaSY Combinator
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@lemonlime.ai

Source

Vulnerability Disclosure

lemonlime-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://lemonlime.ai/security
url: https://lemonlime.ai/security
description: >-
  LemonLime publishes no /.well-known/security.txt (404 on the canonical apex host),
  but its public security page does carry a stated responsible-disclosure posture and
  a dedicated security contact address. There is no bug bounty program and no
  HackerOne/Bugcrowd/Intigriti listing — disclosure is direct-to-vendor by email.
  The mechanical probe (0-working/probe-security-programs.py) independently confirmed
  this page as a disclosure hit; this file is the richer searched capture and is kept
  in preference to the probe's keyword-level output.
policy:
  - https://lemonlime.ai/security
contact:
  - security@lemonlime.ai
security_txt: false
bug_bounty: false
bug_bounty_platform: null
coordinated_disclosure: true
disclosure_terms: >-
  "If you believe you have found a vulnerability or have a security concern, please
  contact us — we aim to acknowledge reports promptly and to work with reporters in
  good faith. Please do not publicly disclose an issue before we have had a reasonable
  opportunity to address it."
evidence:
  - source: https://lemonlime.ai/security
    kind: disclosure page
    keywords: [vulnerability, security research, security issue, 'security@', responsible disclosure, good faith]
  - source: well-known/lemonlime-well-known.yml
    kind: security.txt probe
    result: 404 — no RFC 9116 document published