Vulnerability Disclosure Policy
Last Updated: 10/4/2026
Letscan holds receipts, and receipts say a lot about a person. We take that seriously. If you believe you have found a security vulnerability in Letscan, we want to hear about it, and we would rather hear it from you than read about it later.
1. How to Report
Email us. We read every report, and a person answers it.
To help us move quickly, please include:
- What the issue is, and what an attacker could do with it.
- Clear steps to reproduce it, including the URL, endpoint, or app screen involved.
- The app version and platform, or the browser, if it is relevant.
- Any proof-of-concept code, requests, or screenshots you have.
2. What Happens Next
- We acknowledge your report within 3 business days.
- We give you an initial assessment, including whether we are treating it as a vulnerability, within 10 business days.
- We keep you updated while we work on a fix, and we tell you when it ships.
3. Safe Harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will say so if a third party raises it. Good faith means you stay within the rules below, you stop as soon as you have confirmed a problem, and you give us a reasonable chance to fix it before telling anyone else.
4. In Scope
- letscan.app and its subdomains.
- The Letscan API.
- The Letscan mobile apps for iOS and Android, in their current released versions.
5. Out of Scope
These are not things we will treat as vulnerabilities:
- Denial-of-service, volumetric, brute-force, or load testing of any kind.
- Social engineering, phishing, or physical attacks against our staff, our users, or our providers.
- Services run by third parties that we do not control.
- Scanner output with no demonstrated impact, including missing headers, missing cookie flags, and version-disclosure findings.
- Issues that only affect out-of-date app versions or unsupported browsers.
6. Rules
- Use your own test accounts. Do not access, modify, or keep data belonging to anyone else.
- If you do encounter someone else's personal data, stop, do not save it, and tell us in your report.
- Do not degrade the service for other people.
- Do not disclose the issue publicly until we have fixed it and agreed a date with you.
7. Recognition
We do not run a paid bug bounty today. We will credit you by name for a valid report if you would like us to, and we will say no thank you politely if you would rather stay anonymous.