Lightfield · Vulnerability Disclosure

Lightfield Vulnerability Disclosure

Vulnerability disclosure

Lightfield runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyApplicationsCRMSalesArtificial IntelligenceAgentsCustomer Relationship ManagementGo To MarketProductivitySaaS
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@lightfield.app

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://docs.lightfield.app/security/
policy:
- https://docs.lightfield.app/security/
contact:
- security@lightfield.app
security_txt: null
bug_bounty:
  program: null
  platform: null
  note: No HackerOne / Bugcrowd / Intigriti program was found. Reporting is direct to security@lightfield.app.
safe_harbor: true
safe_harbor_statement: >-
  "Research conducted in good faith under this policy is considered authorized. We will not pursue
  legal action against you for activities consistent with these guidelines. If a third party
  initiates legal action related to your research, we will take steps to make it known that your
  actions were conducted in compliance with this policy."
focus_areas:
- Authentication bypass or privilege escalation
- Unauthorized access to data across workspace boundaries
- Injection attacks or remote code execution
in_scope:
- The Lightfield web application and supporting services
- The Lightfield API
- Lightfield client SDKs
out_of_scope:
- Automated scanning of any kind
- Social engineering, including phishing
- Denial of service attacks
- Attacks requiring physical access to a victim's device
- Theoretical attacks without proof of exploitability
- Missing best practices in HTTP headers, cookies, TLS configuration, or DNS records on the
  marketing site
reporting_requirements:
- A summary of the issue and its potential impact
- Steps to reproduce, including any tools used
- Proof-of-concept code, if available
researcher_conduct:
- Test only against their own accounts or with explicit permission from the account holder.
- Make a good-faith effort to avoid privacy violations, data destruction, or service disruption.
- Report the vulnerability before disclosing it publicly, and give reasonable time to address it.
- Do not attempt to expand or elevate access beyond what is necessary to demonstrate the
  vulnerability.
- Comply with all applicable laws.
related:
  leaked_key_remediation: https://docs.lightfield.app/using-the-api/leaked-api-key-remediation/
evidence:
- source: https://docs.lightfield.app/security/
  kind: vulnerability-disclosure-policy
  status: 200
- source: https://lightfield.app/.well-known/security.txt
  kind: security.txt
  status: 404
notes: >-
  The SECURITY.md files in the Lightfield SDK repositories are Stainless SDK-generator boilerplate
  pointing at security@stainless.com and are NOT Lightfield's disclosure channel; they explicitly
  redirect issues affecting Lightfield's own services to Lightfield. The authoritative policy is the
  docs Security & Compliance page recorded above.