Our commitment
Responsible disclosure policy
The standards we hold ourselves to — and the standards we invite others to hold us to.
How we work
- Public data only. Our standard review uses published databases and information your website already shows every visitor. We do not scan, probe, or test systems we do not own.
- Authorisation before any active testing. Penetration testing or any hands-on assessment happens only after a signed scope-of-work that explicitly authorises it, within the agreed boundaries.
- We never weaponise findings. We don't withhold urgent, dangerous information to pressure a sale. If we discover a serious, live exposure of data, we notify you regardless of whether you become a customer.
- Minimal, confidential data handling. We collect only what's needed to prepare your review, never sell it, and delete it on request.
- No fear, no pressure. A free summary comes first. Whether you go further is entirely your call.
Reporting a vulnerability to us
We hold ourselves to the same standard we recommend. If you believe you've found a security issue in a LASA property, please tell us:
- Email security@lasa.in with details and steps to reproduce.
- Give us a reasonable window to investigate and fix before any public disclosure.
- Please don't access, modify, or delete data that isn't yours, or degrade our services, while testing.
We'll acknowledge your report, keep you updated, and credit you if you'd like once the issue is resolved.
Our machine-readable policy
This policy is also published at /.well-known/security.txt, following the securitytxt.org standard.