Last updated: August 26, 2026
Report privately
Use the contact form or send a concise report to [email protected] with the affected public property, steps to reproduce, likely impact, and the minimum evidence necessary. Do not include credentials, personal information, client data, or a working exploit that is not needed to explain the issue.
Authorization boundaries
No LWS website, WebsiteLinter result, public endpoint, robots file, or disclosure page grants permission to access a system, account, client property, administrative interface, source repository, cloud environment, or non-public data. Test only assets you own or for which you have explicit authorization.
Prohibited activity
- Denial of service, traffic flooding, destructive testing, malware, persistence, or data modification.
- Social engineering, phishing, credential attacks, physical attacks, or targeting personnel or clients.
- Accessing, downloading, retaining, or disclosing personal, confidential, payment, authentication, or client data.
- Automated scanning that ignores rate limits or causes service degradation.
- Public disclosure before we have had a reasonable opportunity to investigate and remediate.
Response and rewards
We will assess good-faith reports and may request clarification. This is not a bug-bounty program and does not promise payment, credit, response time, safe-harbor treatment, or waiver of legal rights. Any testing authorization or reward must be agreed in writing before testing.
