Security Contact
Effective: Pre-launch draft · Last updated: August 29, 2026
Lessware welcomes good-faith reports of security vulnerabilities affecting GetLessware.com, our public APIs, and related pre-launch infrastructure. This page describes how to report issues privately—and what not to send through public channels.
Use the private channel
Email: security@getlessware.com
Use this address for:
- Suspected vulnerabilities in GetLessware.com or public submission endpoints
- Authentication, authorization, or session issues on public surfaces
- Data exposure concerns involving site or form infrastructure
- Abuse patterns that could harm users or Lessware systems
Provide enough detail for us to reproduce the issue: description and potential impact, steps to reproduce, affected URLs or endpoints, proof-of-concept if available (avoid destructive testing), and your contact information for follow-up.
We prefer encrypted email if you have our PGP key on file. A PGP key will be published at this page before broad public promotion of the site. Until then, use standard TLS email to security@getlessware.com.
Do not use the public ideas form
Security vulnerabilities must not be submitted through the public ideas form (/ideas) or other public comment channels.
Public submissions may be published, processed by AI when permitted by the submitter, or visible to staff workflows not designed for coordinated disclosure. Reporting through the wrong channel can increase risk to users and may delay remediation.
For product ideas unrelated to security, use /ideas and the AI Participation Policy.
Safe harbor for good-faith research
Lessware supports responsible disclosure. If you make a good-faith effort to avoid privacy violations, service degradation, and data destruction; do not access accounts or data that are not your own except as strictly necessary to demonstrate the issue; and give us reasonable time to investigate and remediate before public disclosure—we will not pursue legal action against you solely for security research that complies with this page and applicable law.
We cannot authorize testing against third-party services (hosting providers, email vendors, etc.). Do not test outside the scope of Lessware-controlled systems.
What to expect
| Stage | Our intent |
|---|---|
| Acknowledgment | We aim to acknowledge receipt within three business days once monitoring is active. |
| Triage | We assess severity, scope, and affected systems. |
| Remediation | We work to fix validated issues appropriate to our pre-launch stage. |
| Communication | We coordinate disclosure timing with you when possible. We may credit researchers who request recognition and who comply with this policy. |
Pre-launch, Lessware operates with founder-led response processes. We do not operate a 24/7 security operations center or claim enterprise-grade incident maturity we have not yet built.
Out of scope
The following are generally out of scope for vulnerability rewards or urgent triage:
- Social engineering of Lessware staff or users
- Physical security issues unrelated to digital services
- Denial-of-service attacks or volumetric testing
- Issues in third-party services outside Lessware's control (report to the vendor)
- Missing security headers or best practices with no demonstrated exploit
- Spam or content abuse on public forms (report to legal@getlessware.com)
Security and marketing claims
Lessware does not describe GetLessware.com as having "bank-level security," "military-grade encryption," or similar unsupported claims. This contact page exists so researchers and users can reach us directly as our security practices grow with the product.
Consumer financial data connectivity (for example, via Plaid) is not live on GetLessware.com. The public site is intentionally separated from financial-application secrets and data stores.
Contact summary
| Purpose | Channel |
|---|---|
| Security vulnerabilities | security@getlessware.com |
| Privacy requests | privacy@getlessware.com |
| General legal | legal@getlessware.com |
| Public product ideas | /ideas on GetLessware.com (not for security issues) |