Laucked is an offensive security firm. We hold ourselves to the same standard we ask of our clients, and we welcome reports from the security community.
If you believe you have found a security issue in one of our repositories, on laucked.com, or in any service we operate, please report it privately.
- Email: contact@laucked.com
- Subject: include
[Security]and the affected asset - PGP: available on request for sensitive reports
Please do not open a public issue, pull request, or social media post for a suspected vulnerability until we have had a chance to address it.
A good report helps us reproduce and fix the issue quickly. Where possible, include:
- The affected asset (repository, URL, or endpoint)
- A clear description of the issue and its impact
- Step-by-step reproduction details
- Any proof-of-concept, logs, or screenshots
- Your assessment of severity
When you report in good faith, you can expect:
- An acknowledgement within 2 business days
- An initial assessment within 5 business days
- Regular updates until the issue is resolved
- Public credit once the fix is shipped, if you would like it
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data destruction, and service disruption
- Only interact with accounts they own or have explicit permission to test
- Do not exploit a finding beyond what is necessary to demonstrate it
- Give us a reasonable window to remediate before any public disclosure
If you are unsure whether an action is permitted, ask first at contact@laucked.com.
The following are generally not eligible:
- Findings from automated scanners without a demonstrated, exploitable impact
- Denial-of-service or volumetric testing
- Social engineering of our team, clients, or vendors
- Physical attacks or access to facilities
- Reports affecting unsupported or third-party dependencies without a working exploit
Thank you for helping keep Laucked and its users safe.