Vulnerability Disclosure Program
At Lamatic, we believe in collaborating with the global security researcher community to enhance the security of our products. By welcoming researchers to identify vulnerabilities in our systems, we aim to make our products more secure while fostering a cooperative security ecosystem. To this end, we reward researchers for their valuable contributions.
Scope of the Program
In Scope
The following areas and vulnerabilities are included in the Vulnerability Disclosure Program:
-
Products
- Lamatic.ai Studio: only the web application hosted at studio.lamatic.ai is in scope.
-
Vulnerability Categories
- Cross-Site Scripting (XSS)
- SQL Injection
- Authentication flaws
- Data leakage
- Privilege escalation
Out of Scope
The following are not covered by the program:
- Any asset or subdomain other than studio.lamatic.ai
- Social engineering attacks (e.g., phishing)
- Physical security vulnerabilities
- Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
- Brute-force attacks against authentication or rate-limited endpoints
- Use of non-application attack vectors such as machine takeover, cookie takeover, local privilege escalation, or network sniffing
- Findings based on use of intrusive tools such as Burp Suite, Wireshark, or similar packet interception/analyzer tools
- Third-party integrations, dependencies, or services not owned or controlled by Lamatic
Submission Guidelines
Security researchers are required to provide detailed information about identified vulnerabilities. Submissions should include:
- A clear description of the vulnerability
- Step-by-step instructions to reproduce the issue
- An impact analysis outlining the potential risk
- Supporting evidence such as screenshots, videos, or scripts
- Recommendations for remediation
Response Times
We strive to provide timely responses to all submissions:
- Initial response: 24 hours
- Severity assessment: 20 business days
- Status updates: Every 30 business days
- Payment processing: Within 60 days of validation
Review Process
| Step | Description |
|---|---|
| 1. Acknowledgment | Confirm receipt of the report within 24–48 hours. Assign a unique Reference ID to track the submission. |
| 2. Initial Assessment | - Validate the authenticity of the issue. - Perform a Duplicate Check to ensure the bug hasn’t been previously reported. - Note that multiple reports within the same exploit chain are considered one vulnerability. - Share an NDA if necessary. |
| 3. Severity Analysis | Assess the severity using a standard rating system such as CVSS: - Critical: Immediate, widespread impact (e.g., RCE, data breaches). - High: Significant functionality or security risks. - Medium: Moderate impact. - Low: Minor risks. |
| 4. Assignment & Prioritization | Assign the validated issue to the appropriate team and prioritize based on severity. |
| 5. Development & Fixing | Address the issue based on priority and ensure timely resolution. |
| 6. Researcher Verification | Notify the researcher upon resolving the issue. Provide testing environments or evidence (e.g., logs, screenshots) for verification. |
| 7. Reward & Closure | Issue the reward based on the severity, impact, and uniqueness of the vulnerability. |
| 8. Post-Resolution Analysis | Conduct a root cause analysis to identify gaps in code review, testing, or system architecture. |
Rules of Engagement
To ensure ethical conduct, researchers are required to adhere to the following guidelines:
| Do’s | Don’ts |
|---|---|
| Test only within the defined scope (studio.lamatic.ai). | Do not test on any other Lamatic domains or services. |
| Avoid impacting production systems. | Do not use automated tools (e.g., Burp Suite, Wireshark) or network-level scanners. |
| Report vulnerabilities immediately. | Do not exploit vulnerabilities beyond proof-of-concept or attempt denial of service. |
| Operate responsibly and respect user privacy. | Do not attempt brute-force, credential stuffing, or machine-level exploitation. |
| Submit logically distinct vulnerabilities as separate reports. | Do not submit multiple reports from the same exploit chain, as these will be grouped as one vulnerability. |
Legal Protections
Safe Harbor Clause
Lamatic provides safe harbor for researchers acting in good faith, ensuring protection from legal consequences as long as they:
- Operate within the defined scope and guidelines
- Avoid compromising user data
- Do not disrupt services
- Responsibly report vulnerabilities through the program
Disclosure Restrictions
By submitting a vulnerability report, you agree to abide by Lamatic’s Terms & Conditions and the conditions outlined in this program.
- All submitted reports are confidential and must not be shared publicly, including on social media, blogs, forums, or other channels, regardless of their resolution status.
- Even if a vulnerability report is marked as invalid, it is strictly prohibited to disclose any details of the finding without explicit written consent from Lamatic.
- Breaching these terms may disqualify you from receiving a reward and could result in legal action under applicable laws.
Rewards
We greatly appreciate responsible disclosures and will reward eligible contributors with exclusive goodies and swag as a token of thanks.
Note: Our Vulnerability Disclosure Program (VDP) does not include any form of monetary compensation.
Thank you for contributing to the security of Lamatic’s products!