Security at Lifted Holdings
We build and operate payment, point-of-sale, vending and signage systems. This page is where we publish what we find, and how to reach us if you find something.
Report a security issue
Email will@liftedholdings.com. We aim to acknowledge within one business day. Machine-readable contact details are published at /.well-known/security.txt, and our handling commitments are in the vulnerability disclosure policy.
We do not operate a paid bug bounty. We do credit reporters who want credit, and we will not pursue legal action against good-faith research conducted within the policy.
Advisories
Findings from our own investigations, published with full indicators so other defenders can act on them. See all advisories.
How we handle incidents
Three commitments that govern everything on this page:
- We publish indicators, not accusations. Advisories state confidence levels and separate what was observed from what was inferred. Every advisory carries a section describing what we could not establish.
- We notify affected parties before we publish. Where a vendor or third party is involved, they hear from us first, and we say when and how in the advisory itself.
- We do not overstate scope. If we can demonstrate that one account was affected, we say one account — regardless of how large the surrounding organisation is.
Our own posture
Lifted Holdings operates in payments. Card data handling is scoped to validated service providers and gateway-hosted fields; we publish no claim about a certification we do not hold. Questions from customers, partners and underwriters about our controls should go to will@liftedholdings.com.