Responsible Disclosure
Last updated: 21 August 2026
LifeOS AI ("we") values the security community and welcomes responsible disclosure of vulnerabilities that could affect our Service or our users' data. This page explains how to report a vulnerability and what to expect. We are a company registered in the Republic of South Africa.
1. Reporting a vulnerability
If you believe you have discovered a security vulnerability, please report it to us privately via our Contact page, selecting the security option where available. Include enough detail for us to reproduce or investigate the issue, such as a description, steps, and any relevant identifiers. Please do not publish the vulnerability or exploit details publicly until we have had a reasonable opportunity to investigate and respond.
2. Guidelines for responsible reporting
- Test only within the scope of your own account; do not access or attempt to access other users' data.
- Avoid actions that could degrade, disrupt, or destroy the Service or its data.
- Do not use automated scanners in a way that generates excessive traffic or noise.
- Do not exploit the vulnerability for financial gain or to obtain personal data.
- Provide reasonable time for us to investigate and remediate before any public disclosure.
3. What we ask you not to do
Activities such as social engineering of our staff or users, physical attacks, denial-of-service attacks, and accessing or altering data that is not your own are out of scope and may be unlawful. Reports arising from such activities are not eligible for acknowledgement under this policy.
4. Our commitment
We will acknowledge receipt of good-faith reports, investigate them promptly, and keep you informed of progress. We will not take legal action against reporters who follow these guidelines and act in good faith. We may publicly credit reporters with their consent once a vulnerability is resolved.
5. Changes to this policy
We may update this Responsible Disclosure policy from time to time. Material changes will be reflected in the "Last updated" date above.
