Life360 · Vulnerability Disclosure

Life360 Vulnerability Disclosure

Vulnerability disclosure

Life360 runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyConsumerFamily SafetyLocationGPS TrackingBluetooth TrackersMobile AppsDriving SafetyWearablesSubscription
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:responsibledisclosure@life360.com
Contact
https://hackerone.com/life360

Source

Vulnerability Disclosure

life360-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://www.life360.com/.well-known/security.txt
policy:
- https://hackerone.com/life360
contact:
- mailto:responsibledisclosure@life360.com
- https://hackerone.com/life360
preferred_languages:
- en
canonical: https://www.life360.com/.well-known/security.txt
hiring: https://www.life360.com/careers/
expires: '2022-12-31T23:59:00.000Z'
expired: true
evidence:
- source: well-known/life360-security.txt
  kind: security.txt
  http_status: 200
- source: https://www.life360.com/.well-known/security.txt
  kind: security.txt (live probe)
  http_status: 200
notes: >-
  Life360 runs a coordinated disclosure program on HackerOne and publishes a
  dedicated responsibledisclosure@life360.com mailbox, both advertised through a
  conformant RFC 9116 security.txt. The one defect is the Expires field, which is
  set to 2022-12-31 — the document is stale by the standard's own rules and
  should be re-issued. No separate responsible-disclosure page exists on
  life360.com; the security.txt and the HackerOne program are the disclosure
  surface.