Skip to content
Lessware

Security Contact

Effective: Pre-launch draft · Last updated: August 29, 2026

Lessware welcomes good-faith reports of security vulnerabilities affecting GetLessware.com, our public APIs, and related pre-launch infrastructure. This page describes how to report issues privately—and what not to send through public channels.

Use the private channel

Email: security@getlessware.com

Use this address for:

  • Suspected vulnerabilities in GetLessware.com or public submission endpoints
  • Authentication, authorization, or session issues on public surfaces
  • Data exposure concerns involving site or form infrastructure
  • Abuse patterns that could harm users or Lessware systems

Provide enough detail for us to reproduce the issue: description and potential impact, steps to reproduce, affected URLs or endpoints, proof-of-concept if available (avoid destructive testing), and your contact information for follow-up.

We prefer encrypted email if you have our PGP key on file. A PGP key will be published at this page before broad public promotion of the site. Until then, use standard TLS email to security@getlessware.com.

Do not use the public ideas form

Security vulnerabilities must not be submitted through the public ideas form (/ideas) or other public comment channels.

Public submissions may be published, processed by AI when permitted by the submitter, or visible to staff workflows not designed for coordinated disclosure. Reporting through the wrong channel can increase risk to users and may delay remediation.

For product ideas unrelated to security, use /ideas and the AI Participation Policy.

Safe harbor for good-faith research

Lessware supports responsible disclosure. If you make a good-faith effort to avoid privacy violations, service degradation, and data destruction; do not access accounts or data that are not your own except as strictly necessary to demonstrate the issue; and give us reasonable time to investigate and remediate before public disclosure—we will not pursue legal action against you solely for security research that complies with this page and applicable law.

We cannot authorize testing against third-party services (hosting providers, email vendors, etc.). Do not test outside the scope of Lessware-controlled systems.

What to expect

StageOur intent
AcknowledgmentWe aim to acknowledge receipt within three business days once monitoring is active.
TriageWe assess severity, scope, and affected systems.
RemediationWe work to fix validated issues appropriate to our pre-launch stage.
CommunicationWe coordinate disclosure timing with you when possible. We may credit researchers who request recognition and who comply with this policy.

Pre-launch, Lessware operates with founder-led response processes. We do not operate a 24/7 security operations center or claim enterprise-grade incident maturity we have not yet built.

Out of scope

The following are generally out of scope for vulnerability rewards or urgent triage:

  • Social engineering of Lessware staff or users
  • Physical security issues unrelated to digital services
  • Denial-of-service attacks or volumetric testing
  • Issues in third-party services outside Lessware's control (report to the vendor)
  • Missing security headers or best practices with no demonstrated exploit
  • Spam or content abuse on public forms (report to legal@getlessware.com)

Security and marketing claims

Lessware does not describe GetLessware.com as having "bank-level security," "military-grade encryption," or similar unsupported claims. This contact page exists so researchers and users can reach us directly as our security practices grow with the product.

Consumer financial data connectivity (for example, via Plaid) is not live on GetLessware.com. The public site is intentionally separated from financial-application secrets and data stores.

Contact summary

PurposeChannel
Security vulnerabilitiessecurity@getlessware.com
Privacy requestsprivacy@getlessware.com
General legallegal@getlessware.com
Public product ideas/ideas on GetLessware.com (not for security issues)