← Trust & Security

RESPONSIBLE DISCLOSURE

Report suspected security issues without creating additional risk.

What to report

Suspected unauthorised access, authentication/session weakness, cross-customer data exposure, injection, privilege or authority bypass, material secret exposure, payment/security-control bypass or another credible vulnerability affecting Levqor-controlled systems.

Safe testing

Use your own accounts/data where possible. Do not access, modify, download or retain another person's data; do not degrade availability; do not send spam, social-engineer users, exfiltrate secrets, perform persistence, execute destructive payloads or continue exploitation after enough evidence exists to demonstrate the issue.

What to include

Provide the affected URL/feature, concise reproduction steps, observed and expected behaviour, relevant timestamps/request IDs and the minimum evidence needed to reproduce safely. Do not include unnecessary personal data or credentials.

Reporting route

Use the current Levqor support/contact path and mark the report as a security issue. Levqor does not rely on an unverified dedicated security mailbox as the sole reporting route; any future dedicated security mailbox must be independently proved before it is represented as release-critical.

Handling

Levqor may prioritise containment, request clarification and preserve relevant logs/evidence. This page does not promise a bounty, specific response deadline or safe-harbour beyond rights available under applicable law; responsible, good-faith reporting will be considered in context.

Customer truth: Levqor does not guarantee sales, revenue, ROI or closed business. First Three is governed by the written qualification and commercial terms agreed before activity begins.