Security Policy
Report security issues responsibly. Do not exploit, disclose, disrupt systems or access data that is not yours.
1. Reporting channel
Email security reports to security@lisar.io. Include affected domain, account/profile context if relevant, steps to reproduce, expected impact, timestamps and evidence.
2. Safe testing boundaries
Non-destructive testing of public web pages, setup flows and authentication screens is permitted. Infrastructure scanning, denial-of-service testing, credential attacks, social engineering, payment abuse, data exfiltration or attempts to access other users' data are not permitted.
3. Sensitive data
Do not send live passwords, private keys, payment secrets, recovery codes or unrelated personal data. If a proof of concept requires sensitive material, describe the issue first and wait for instructions.
4. Response expectations
Lisar will review reports based on severity, reproducibility and risk. Reports that violate this policy, cause disruption or involve unauthorized access may be treated as abuse.
5. Abuse reports
Security vulnerabilities go to security@lisar.io. Network abuse reports go to abuse@lisar.io.
OpenVPN profile file safety
For OpenVPN setup, download the .ovpn file, then open OpenVPN Connect and choose Upload File. Treat downloaded profile files, private keys and screenshots containing connection secrets as sensitive setup material.