Responsible Disclosure Policy

Last Updated: July 2026

1. Commitment to Security

At Lira Consulting, the security of our data platform, user information, and proprietary intelligence is a top priority. We recognize the important role that security researchers and the broader cybersecurity community play in keeping systems safe. This policy outlines our approach to responsible disclosure and provides guidelines for reporting potential vulnerabilities.

2. Scope

This policy covers all digital assets owned and operated directly by Lira Consulting, including our primary website domains, subdomains, member login portals, and application programming interfaces (APIs). Third-party services, payment gateways, and hosted applications outside of our direct control are out of scope.

3. Safe Harbor

We consider security research and vulnerability disclosure activities conducted in compliance with this policy to be authorized. Lira Consulting will not initiate or support legal action, nor pursue law enforcement investigation, against researchers who conduct their testing in good faith and adhere to these rules of engagement.

4. Rules of Engagement

When conducting vulnerability research on Lira Consulting systems, we require that you:

 Avoid Harm: Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data.

 No Data Exfiltration: Do not access, download, or modify user data, billing information, or proprietary databases. If you encounter sensitive information during your research, halt your activities and report the issue immediately.

 Testing Restrictions: Do not engage in Denial of Service (DoS or DDoS) attacks, spamming, social engineering (including phishing) of our employees or contractors, or physical security testing of our office locations.

 Confidentiality: Keep information about any vulnerabilities you've discovered confidential between yourself and Lira Consulting until we have resolved the issue.

5. Reporting a Vulnerability

If you believe you have found a security vulnerability, please submit a report to our designated security contact. Your report should contain:

1. A clear description of the vulnerability and its potential impact.

2. Detailed steps required to reproduce the issue (including any necessary tools or environmental configurations).

3. Any non-destructive proof-of-concept (PoC) scripts or screenshots.

6. Remediation Timeline

We are committed to addressing reported issues promptly. Upon receiving a vulnerability report, Lira Consulting will:

Action

Expected Timeframe

Acknowledge receipt of your report

Within 5 business days

Provide an initial assessment and timeline for a fix

Within 14 business days

Notify you when the vulnerability has been resolved

Upon deployment of the patch

 

We thank the security community for their efforts in helping protect Lira Consulting and our users.