Responsible Disclosure Policy
Last Updated: July 2026
1. Commitment to Security
At Lira Consulting, the security of our data platform, user information, and proprietary intelligence is a top priority. We recognize the important role that security researchers and the broader cybersecurity community play in keeping systems safe. This policy outlines our approach to responsible disclosure and provides guidelines for reporting potential vulnerabilities.
2. Scope
This policy covers all digital assets owned and operated directly by Lira Consulting, including our primary website domains, subdomains, member login portals, and application programming interfaces (APIs). Third-party services, payment gateways, and hosted applications outside of our direct control are out of scope.
3. Safe Harbor
We consider security research and vulnerability disclosure activities conducted in compliance with this policy to be authorized. Lira Consulting will not initiate or support legal action, nor pursue law enforcement investigation, against researchers who conduct their testing in good faith and adhere to these rules of engagement.
4. Rules of Engagement
When conducting vulnerability research on Lira Consulting systems, we require that you:
● Avoid Harm: Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data.
● No Data Exfiltration: Do not access, download, or modify user data, billing information, or proprietary databases. If you encounter sensitive information during your research, halt your activities and report the issue immediately.
● Testing Restrictions: Do not engage in Denial of Service (DoS or DDoS) attacks, spamming, social engineering (including phishing) of our employees or contractors, or physical security testing of our office locations.
● Confidentiality: Keep information about any vulnerabilities you've discovered confidential between yourself and Lira Consulting until we have resolved the issue.
5. Reporting a Vulnerability
If you believe you have found a security vulnerability, please submit a report to our designated security contact. Your report should contain:
1. A clear description of the vulnerability and its potential impact.
2. Detailed steps required to reproduce the issue (including any necessary tools or environmental configurations).
3. Any non-destructive proof-of-concept (PoC) scripts or screenshots.
6. Remediation Timeline
We are committed to addressing reported issues promptly. Upon receiving a vulnerability report, Lira Consulting will:
|
Action |
Expected Timeframe |
|
Acknowledge receipt of your report |
Within 5 business days |
|
Provide an initial assessment and timeline for a fix |
Within 14 business days |
|
Notify you when the vulnerability has been resolved |
Upon deployment of the patch |
We thank the security community for their efforts in helping protect Lira Consulting and our users.
