RESPONSIBLE DISCLOSURE
Report suspected security issues without creating additional risk.
What to report
Suspected unauthorised access, authentication/session weakness, cross-customer data exposure, injection, privilege or authority bypass, material secret exposure, payment/security-control bypass or another credible vulnerability affecting Levqor-controlled systems.
Safe testing
Use your own accounts/data where possible. Do not access, modify, download or retain another person's data; do not degrade availability; do not send spam, social-engineer users, exfiltrate secrets, perform persistence, execute destructive payloads or continue exploitation after enough evidence exists to demonstrate the issue.
What to include
Provide the affected URL/feature, concise reproduction steps, observed and expected behaviour, relevant timestamps/request IDs and the minimum evidence needed to reproduce safely. Do not include unnecessary personal data or credentials.
Reporting route
Use the current Levqor support/contact path and mark the report as a security issue. Levqor does not rely on an unverified dedicated security mailbox as the sole reporting route; any future dedicated security mailbox must be independently proved before it is represented as release-critical.
Handling
Levqor may prioritise containment, request clarification and preserve relevant logs/evidence. This page does not promise a bounty, specific response deadline or safe-harbour beyond rights available under applicable law; responsible, good-faith reporting will be considered in context.