Coordinated vulnerability disclosure

At Linehub, we are committed to ensuring the security of our systems and protecting our users. Despite our care, vulnerabilities may occur. We appreciate the efforts of security researchers in identifying vulnerabilities and welcome their contributions.

Reporting a vulnerability

If you believe you have discovered a vulnerability, please report it to us responsibly:

What to include

  • Description of the vulnerability and its potential impact;
  • Detailed steps to reproduce the vulnerability;
  • Any relevant screenshots or proof-of-concept.

What we ask from you

To ensure the safety and privacy of our systems, users, and data; please adhere to the following guidelines:

  • Do Not: Publicly disclose vulnerabilities until they are resolved;
  • Do Not: Copy, edit, or delete data;
  • Do Not: Make changes in the system or disrupt our services;
  • Do Not: Attack physical security or third-party applications;
  • Do Not: Introduce malware into the system;
  • Do Not: Use brute-force or distributed denial-of-service attacks;
  • Do Not: Use social engineering or spam;
  • Do Not: Publicly disclose confidential data;
  • Do Not: Exploit vulnerabilities by, for example, downloading more data than is necessary to demonstrate the vulnerability;
  • Do: Delete all confidential data obtained through vulnerabilities as soon as possible;
  • Do: Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services;
  • Do: Provide sufficient information to reproduce the vulnerability so that we can resolve it quickly;
  • Do: Contact us to report a discovered vulnerability responsibly.

What you can expect from us

We promise we will:

  • acknowledge receipt of your report within 5 business days;
  • review and assess the vulnerability;
  • provide you with an estimated timeline for the fix;
  • treat your report as confidential;
  • not share your personal data with third parties without your consent, unless necessary to comply with a legal obligation;
  • accept anonymous vulnerability reports or reports under a pseudonym;
    • It’s important to note that we won’t be able to contact you about the next steps or the progress of remediating the reported vulnerability.
  • if you so choose, provided that the quality of the report is good and not known by us:
    • keep you informed of the progress in solving the problem;
    • include your name as the discoverer of the vulnerability in any communications about the reported problem;
    • include your name on our wall-of-fame to acknowledge your efforts.
  • strive to resolve reported problems as quickly as possible.

Thank you

We greatly appreciate your efforts in helping us maintain the security and integrity of our systems.

Linehub Legal
Have any questions? Contact us!