Terms & policies
Responsible disclosure policy
We want security researchers to tell us what they find — safely. This policy explains how to report a vulnerability, what we promise in return, and the boundaries that protect our users while you work. Last updated: August 2026.
How to report
Send findings through security contact with “Security vulnerability” in the subject. Include what you found, how to reproduce it, and what an attacker could do with it. Reports go directly to the team that runs the platform.
Our commitments
Acknowledgment — we confirm we received your report as quickly as we can, normally within two business days.
Assessment — we investigate, assess severity honestly, and keep you informed as we work.
No legal action for good-faith research — if you follow this policy, we won’t pursue or support legal action against you, and we’ll say so if a third party asks.
Credit — with your permission, we’ll thank you publicly once the issue is fixed.
Safe harbour — what we ask
Test only against your own account and data you’re authorized to touch. Never access, copy or retain other users’ data; if you encounter it by accident, stop and report immediately. No denial-of-service, no social engineering of staff or users, no physical testing, no spam. Don’t disclose the issue publicly until we’ve had a fair chance to fix it — we’ll tell you when it’s resolved.
Scope notes
In scope: the LocuPedia web platform and marketing site. Out of scope: third-party services we link to, and findings that require physical access or amounts of traffic that degrade the service. When in doubt, ask first — a quick question costs nothing and keeps everyone protected.