DocsSecurity & ComplianceVulnerability Disclosure Program

Vulnerability Disclosure Program

At Lamatic, we believe in collaborating with the global security researcher community to enhance the security of our products. By welcoming researchers to identify vulnerabilities in our systems, we aim to make our products more secure while fostering a cooperative security ecosystem. To this end, we reward researchers for their valuable contributions.

Scope of the Program

In Scope

The following areas and vulnerabilities are included in the Vulnerability Disclosure Program:

  1. Products

    • Lamatic.ai Studio: only the web application hosted at studio.lamatic.ai is in scope.
  2. Vulnerability Categories

    • Cross-Site Scripting (XSS)
    • SQL Injection
    • Authentication flaws
    • Data leakage
    • Privilege escalation

Out of Scope

The following are not covered by the program:

  1. Any asset or subdomain other than studio.lamatic.ai
  2. Social engineering attacks (e.g., phishing)
  3. Physical security vulnerabilities
  4. Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
  5. Brute-force attacks against authentication or rate-limited endpoints
  6. Use of non-application attack vectors such as machine takeover, cookie takeover, local privilege escalation, or network sniffing
  7. Findings based on use of intrusive tools such as Burp Suite, Wireshark, or similar packet interception/analyzer tools
  8. Third-party integrations, dependencies, or services not owned or controlled by Lamatic

Submission Guidelines

Security researchers are required to provide detailed information about identified vulnerabilities. Submissions should include:

  1. A clear description of the vulnerability
  2. Step-by-step instructions to reproduce the issue
  3. An impact analysis outlining the potential risk
  4. Supporting evidence such as screenshots, videos, or scripts
  5. Recommendations for remediation

Response Times

We strive to provide timely responses to all submissions:

  1. Initial response: 24 hours
  2. Severity assessment: 20 business days
  3. Status updates: Every 30 business days
  4. Payment processing: Within 60 days of validation

Review Process

StepDescription
1. AcknowledgmentConfirm receipt of the report within 24–48 hours. Assign a unique Reference ID to track the submission.
2. Initial Assessment- Validate the authenticity of the issue.
- Perform a Duplicate Check to ensure the bug hasn’t been previously reported.
- Note that multiple reports within the same exploit chain are considered one vulnerability.
- Share an NDA if necessary.
3. Severity AnalysisAssess the severity using a standard rating system such as CVSS:
- Critical: Immediate, widespread impact (e.g., RCE, data breaches).
- High: Significant functionality or security risks.
- Medium: Moderate impact.
- Low: Minor risks.
4. Assignment & PrioritizationAssign the validated issue to the appropriate team and prioritize based on severity.
5. Development & FixingAddress the issue based on priority and ensure timely resolution.
6. Researcher VerificationNotify the researcher upon resolving the issue. Provide testing environments or evidence (e.g., logs, screenshots) for verification.
7. Reward & ClosureIssue the reward based on the severity, impact, and uniqueness of the vulnerability.
8. Post-Resolution AnalysisConduct a root cause analysis to identify gaps in code review, testing, or system architecture.

Rules of Engagement

To ensure ethical conduct, researchers are required to adhere to the following guidelines:

Do’sDon’ts
Test only within the defined scope (studio.lamatic.ai).Do not test on any other Lamatic domains or services.
Avoid impacting production systems.Do not use automated tools (e.g., Burp Suite, Wireshark) or network-level scanners.
Report vulnerabilities immediately.Do not exploit vulnerabilities beyond proof-of-concept or attempt denial of service.
Operate responsibly and respect user privacy.Do not attempt brute-force, credential stuffing, or machine-level exploitation.
Submit logically distinct vulnerabilities as separate reports.Do not submit multiple reports from the same exploit chain, as these will be grouped as one vulnerability.

Safe Harbor Clause

Lamatic provides safe harbor for researchers acting in good faith, ensuring protection from legal consequences as long as they:

  1. Operate within the defined scope and guidelines
  2. Avoid compromising user data
  3. Do not disrupt services
  4. Responsibly report vulnerabilities through the program

Disclosure Restrictions

By submitting a vulnerability report, you agree to abide by Lamatic’s Terms & Conditions and the conditions outlined in this program.

  • All submitted reports are confidential and must not be shared publicly, including on social media, blogs, forums, or other channels, regardless of their resolution status.
  • Even if a vulnerability report is marked as invalid, it is strictly prohibited to disclose any details of the finding without explicit written consent from Lamatic.
  • Breaching these terms may disqualify you from receiving a reward and could result in legal action under applicable laws.

Rewards

We greatly appreciate responsible disclosures and will reward eligible contributors with exclusive goodies and swag as a token of thanks.

Note: Our Vulnerability Disclosure Program (VDP) does not include any form of monetary compensation.


Thank you for contributing to the security of Lamatic’s products!

Was this page useful?

Subscribe to updates