Lightfield · Vulnerability Disclosure

Lightfield Vulnerability Disclosure

Vulnerability disclosure

Lightfield runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyApplicationCRMSalesArtificial IntelligenceAgentsCustomer Relationship ManagementGo-To-MarketProductivitySoftware-as-a-Service
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@lightfield.app

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://docs.lightfield.app/security/
policy:
- https://docs.lightfield.app/security/
contact:
- security@lightfield.app
security_txt: null
bug_bounty:
  program: null
  platform: null
  note: No HackerOne / Bugcrowd / Intigriti program was found. Reporting is direct to security@lightfield.app.
safe_harbor: true
safe_harbor_statement: >-
  "Research conducted in good faith under this policy is considered authorized. We will not pursue
  legal action against you for activities consistent with these guidelines. If a third party
  initiates legal action related to your research, we will take steps to make it known that your
  actions were conducted in compliance with this policy."
focus_areas:
- Authentication bypass or privilege escalation
- Unauthorized access to data across workspace boundaries
- Injection attacks or remote code execution
in_scope:
- The Lightfield web application and supporting services
- The Lightfield API
- Lightfield client SDKs
out_of_scope:
- Automated scanning of any kind
- Social engineering, including phishing
- Denial of service attacks
- Attacks requiring physical access to a victim's device
- Theoretical attacks without proof of exploitability
- Missing best practices in HTTP headers, cookies, TLS configuration, or DNS records on the
  marketing site
reporting_requirements:
- A summary of the issue and its potential impact
- Steps to reproduce, including any tools used
- Proof-of-concept code, if available
researcher_conduct:
- Test only against their own accounts or with explicit permission from the account holder.
- Make a good-faith effort to avoid privacy violations, data destruction, or service disruption.
- Report the vulnerability before disclosing it publicly, and give reasonable time to address it.
- Do not attempt to expand or elevate access beyond what is necessary to demonstrate the
  vulnerability.
- Comply with all applicable laws.
related:
  leaked_key_remediation: https://docs.lightfield.app/using-the-api/leaked-api-key-remediation/
evidence:
- source: https://docs.lightfield.app/security/
  kind: vulnerability-disclosure-policy
  status: 200
- source: https://lightfield.app/.well-known/security.txt
  kind: security.txt
  status: 404
notes: >-
  The SECURITY.md files in the Lightfield SDK repositories are Stainless SDK-generator boilerplate
  pointing at security@stainless.com and are NOT Lightfield's disclosure channel; they explicitly
  redirect issues affecting Lightfield's own services to Lightfield. The authoritative policy is the
  docs Security & Compliance page recorded above.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lightfield-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.