Lessen · Vulnerability Disclosure

Lessen Vulnerability Disclosure

Vulnerability disclosure

Lessen runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyProptechReal EstateProperty ManagementFacilities ManagementField Service ManagementWork Order ManagementMaintenanceMarketplaceConstruction
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@lessen.com
Contact
notices@lessen.com

Source

Vulnerability Disclosure

lessen-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://www.lessen.com/legal/security-policy
policy:
- https://www.lessen.com/legal/security-policy
contact:
- security@lessen.com
- notices@lessen.com
phone:
- '+1-866-663-0866'
bug_bounty: null
platforms: []
security_txt: false
notes: >-
  Lessen publishes a Security Policy under /legal/ that names security@lessen.com
  as the reporting address and asks users to notify Lessen of potential or actual
  security-related breaches, incidents or concerns. There is no formal coordinated
  vulnerability disclosure program, no published safe-harbor language, no response
  SLA, and no bug bounty on HackerOne, Bugcrowd or Intigriti. No RFC 9116
  /.well-known/security.txt is served on lessen.com or www.lessen.com (both 404).
evidence:
- source: https://www.lessen.com/legal/security-policy
  kind: security-policy-page
  keywords:
  - security@lessen.com
  - security-related breaches, incidents or concerns
  - SSL encryption
- source: https://www.lessen.com/.well-known/security.txt
  kind: security.txt
  status: 404