Vulnerability Disclosure Policy
Effective 2026-07-28 · Version 1.0Lonzo handles some of the most sensitive data people own — their email, calendar, contacts, and tasks. We treat the security of that data as a first-order responsibility, and we welcome the security-research community's help in keeping it safe. This policy explains how to report a vulnerability to us and what you can expect in return.
How to report
Send your report to security@lonzo.ai. Please include enough detail for us to reproduce and assess the issue: the affected component or URL, the steps to reproduce, the impact you believe it has, and any proof-of-concept material. If you would like, tell us how you would like to be credited.
We will acknowledge your report within 5 business days and work with you through remediation. Please give us a reasonable opportunity to investigate and fix the issue before you disclose it publicly.
Safe harbor — good-faith research
If you make a good-faith effort to comply with this policy during your research, we will consider that research to be authorized, and:
- We will not pursue or support legal action against you in connection with that research, including under computer-misuse or anti-circumvention laws or under our Terms of Use.
- We will not consider your good-faith activity to be a breach of our Terms of Use for the purpose of that research.
This safe harbor applies only to good-faith research that stays within the scope and rules below. It does not, and cannot, waive the rights of any third party. If legal action is initiated by a third party against you for activity conducted under this policy, we will make it known that your actions were authorized under this policy.
Rules of engagement
While researching, please:
- Do not access, modify, delete, or exfiltrate data that is not yours. Use only test accounts you control. If you encounter another person's data during testing, stop immediately, do not view or retain it beyond what is necessary to document the finding, and tell us.
- Do not degrade or disrupt the service. No denial-of-service, no automated high-volume scanning that impairs availability, and no spam or social-engineering of our staff or users.
- Do not use social engineering, phishing, or physical attacks against our staff, users, or facilities.
- Keep findings confidential until we have had a reasonable opportunity to remediate and have coordinated disclosure with you.
In scope
- lonzo.ai and its subdomains, including the Lonzo browser application, its APIs, and the production hosts they resolve to.
- The Lonzo Android application.
- Vulnerabilities that could affect the confidentiality, integrity, or availability of customer data.
Out of scope
- Findings in third-party services we rely on (for example Google, Google Play, or AWS) — report those to the relevant provider. Our current sub-processors are listed at lonzo.ai/legal/subprocessors.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Denial-of-service, volumetric, or resource-exhaustion attacks.
- Social engineering, phishing, and physical-security issues.
- Missing security headers, cookie flags, or configuration best-practices with no demonstrated exploit.
- Vulnerabilities requiring a rooted/jailbroken device, a compromised account, or a privileged position that is itself out of scope.
Coordinated disclosure
We ask that you give us a reasonable time to remediate before disclosing publicly — 90 days from your initial report. We are happy to coordinate timing and public credit with you, and we will keep you informed of our progress.
No bug-bounty program
This is not a paid program. We do not offer monetary rewards or a bug bounty for vulnerability reports. Instead, we run a recognition-only program: we deeply appreciate responsible reports and, with your permission, we will credit you on our Security Researcher acknowledgements list once an issue is resolved. Credit is opt-in — tell us in your report if you would like to be listed and how you would like to be named.