Legal

Responsible Disclosure Policy

Version 1.0 · Effective Date: January 1, 2026 · Last Updated: January 1, 2026


At Lextiff, protecting the security, confidentiality, and integrity of our customers' information is a top priority.

We recognize the important role played by security researchers, customers, and the broader security community in helping identify potential vulnerabilities. If you believe you have discovered a security vulnerability affecting Lextiff, we encourage you to report it responsibly in accordance with this policy.

We are committed to investigating legitimate security reports promptly and working with researchers in good faith to resolve verified issues.

1. Scope

This Responsible Disclosure Policy applies to vulnerabilities affecting:

  • The Lextiff web application
  • The Lextiff public website
  • Customer Portal
  • Client Intake Portal
  • Public APIs
  • Authentication services
  • Infrastructure owned and operated by Lextiff

This policy applies only to systems owned or operated by Lextiff. It does not apply to third-party products, services, or websites.

2. How to Report a Vulnerability

Please send vulnerability reports to:

Security Team

security@lextiff.com

Please include as much information as possible, including:

  • Description of the vulnerability
  • Affected URL or feature
  • Steps to reproduce
  • Expected behavior
  • Actual behavior
  • Screenshots (if applicable)
  • Proof-of-concept code (if applicable)
  • Your contact information

Providing complete information helps us investigate more quickly.

3. Our Commitment

If you submit a vulnerability report in good faith, Lextiff will make reasonable efforts to:

  • Acknowledge receipt of your report, typically within 3 business days
  • Review and validate the reported issue
  • Keep you informed of the investigation status where appropriate
  • Work to remediate confirmed vulnerabilities based on severity and risk
  • Notify you when the issue has been resolved, where appropriate

Resolution timelines vary depending on the complexity and impact of the reported issue.

4. Good Faith Research

We consider security research to be conducted in good faith when you:

  • Act to improve the security of the Services
  • Avoid actions that could harm Customers or the Services
  • Respect user privacy and confidentiality
  • Report vulnerabilities promptly after discovery
  • Give us a reasonable opportunity to investigate and remediate the issue before public disclosure

5. Rules of Engagement

While conducting security research, you agree to:

  • Make every effort to avoid accessing, modifying, or deleting Customer Data
  • Stop testing immediately if you encounter confidential information belonging to another user
  • Avoid service disruption or denial-of-service testing
  • Avoid excessive automated scanning that could impact platform availability
  • Test only the minimum functionality necessary to demonstrate the issue
  • Maintain the confidentiality of any information encountered during testing

6. Out of Scope

The following activities are outside the scope of this policy and are not authorized:

  • Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) attacks
  • Physical attacks against personnel or facilities
  • Social engineering of customers or employees
  • Phishing attacks
  • Spam
  • Malware deployment
  • Ransomware testing
  • Brute-force attacks against customer accounts
  • Credential stuffing
  • Automated vulnerability scanning that significantly impacts service availability
  • Accessing or modifying Customer Data without authorization
  • Testing third-party systems not owned by Lextiff
  • Extortion or demands for payment in exchange for vulnerability information

7. Safe Harbor

Provided you:

  • Act in good faith
  • Follow this Responsible Disclosure Policy
  • Avoid intentionally accessing Customer Data
  • Do not exploit vulnerabilities beyond what is reasonably necessary to demonstrate the issue
  • Promptly report discovered vulnerabilities

Lextiff will not intentionally pursue legal action against you solely for your security research conducted in accordance with this policy.

This Safe Harbor does not apply to activities that:

  • Violate applicable law
  • Result in unauthorized disclosure of Customer Data
  • Cause service disruption
  • Damage systems or data
  • Involve extortion, fraud, or malicious conduct

8. Public Disclosure

We request that researchers do not publicly disclose vulnerabilities until:

  • Lextiff has confirmed the issue;
  • We have had a reasonable opportunity to investigate and remediate it; and
  • We have mutually agreed on an appropriate disclosure timeline where applicable.

Coordinated disclosure helps protect our Customers while allowing security issues to be resolved responsibly.

9. Bug Bounty

At this time, Lextiff does not operate a public bug bounty or monetary reward program.

While we greatly appreciate responsible security research, submission of a vulnerability report does not create any expectation of compensation.

We may, at our sole discretion, acknowledge significant contributions or offer non-monetary recognition.

10. Security Updates

Confirmed vulnerabilities are prioritized based on factors including:

  • Severity
  • Exploitability
  • Customer impact
  • Data exposure
  • Availability impact
  • Operational risk

Not all vulnerabilities require immediate public disclosure. Lextiff reserves the right to determine appropriate remediation timelines.

11. Changes to This Policy

Lextiff may update this Responsible Disclosure Policy from time to time to reflect changes in our security practices, infrastructure, or applicable law. The Last Updated date at the top of this page indicates the most recent revision.

Contact

For all security-related matters, including vulnerability reports and security inquiries, please contact:

Security Team, Lextiff (Operated by Canvas Chrome Designs)

Email: security@lextiff.com

Website: https://www.lextiff.com