Skip to main content

Responsible disclosure

Do not publish suspected vulnerabilities, credentials, private infrastructure details, or exploit material in a public issue.

Until a dedicated security mailbox and encrypted intake channel are published, design partners and reviewers should use the private contact channel established in their Luvion correspondence and mark the message Security report.

Include, when safe:

  • affected component and version or commit;
  • concise impact and preconditions;
  • reproducible steps using test assets only;
  • relevant request IDs, logs, or evidence digests with secrets removed; and
  • whether the issue may be actively exploitable.

Luvion will acknowledge receipt through the same private channel, preserve the report as restricted information, and coordinate validation and remediation before any disclosure. A formal response-time policy will be published before production onboarding.

No production bug-bounty claim

The current pilot has no public bug-bounty program and no production-value authorization scope. Do not test against systems or assets without explicit written permission.