Vulnerability disclosure policy

If you have found a security issue in a Lifted Holdings product or service, we want to hear about it. This page tells you how to report it and what we commit to in return.

Scope

This policy covers systems operated by Lifted Holdings LLC, including liftedholdings.com, liftedpayments.com, agevend.com, and the products served from them.

It does not cover third-party services we consume. If the issue is in a vendor's product, please report it to that vendor. We are glad to help route it if you are unsure who owns the system.

How to report

Email will@liftedholdings.com with the subject line beginning [SECURITY].

A useful report includes: what the issue is, the affected URL or component, the steps to reproduce it, what an attacker could achieve, and anything you need from us to demonstrate it. Screenshots and request/response captures help. Reports in any format are still welcome — a rough report you actually send beats a polished one you do not.

What we commit to

StageOur commitment
AcknowledgementWithin one business day, from a human.
Initial assessmentWithin five business days, including whether we consider it in scope and our severity read.
Progress updatesAt least every ten business days while the issue is open.
CreditPublic credit in the fix note or an advisory if you want it, anonymity if you prefer. Your choice, and we will ask.
LegalWe will not pursue or support legal action against research conducted in good faith under this policy.

We do not operate a paid bug bounty. We would rather tell you that plainly than imply a reward that does not exist.

What we ask of you

If you find something that is actively being exploited

Say so in the subject line and call 855-678-5142. We will treat active exploitation as an incident immediately rather than routing it through the normal queue.

Our own disclosures

When we find something affecting someone else, we follow the same principles we ask of you: we notify the affected party first, we state what we can and cannot demonstrate, and we publish indicators so other defenders can protect themselves. Our published findings are in security advisories.