Back to Home

Vulnerability Disclosure Policy

Last Updated: 10/4/2026

Letscan holds receipts, and receipts say a lot about a person. We take that seriously. If you believe you have found a security vulnerability in Letscan, we want to hear about it, and we would rather hear it from you than read about it later.

1. How to Report

Email us. We read every report, and a person answers it.

security@netzarlabs.com

To help us move quickly, please include:

  • What the issue is, and what an attacker could do with it.
  • Clear steps to reproduce it, including the URL, endpoint, or app screen involved.
  • The app version and platform, or the browser, if it is relevant.
  • Any proof-of-concept code, requests, or screenshots you have.

2. What Happens Next

  • We acknowledge your report within 3 business days.
  • We give you an initial assessment, including whether we are treating it as a vulnerability, within 10 business days.
  • We keep you updated while we work on a fix, and we tell you when it ships.

3. Safe Harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will say so if a third party raises it. Good faith means you stay within the rules below, you stop as soon as you have confirmed a problem, and you give us a reasonable chance to fix it before telling anyone else.

4. In Scope

  • letscan.app and its subdomains.
  • The Letscan API.
  • The Letscan mobile apps for iOS and Android, in their current released versions.

5. Out of Scope

These are not things we will treat as vulnerabilities:

  • Denial-of-service, volumetric, brute-force, or load testing of any kind.
  • Social engineering, phishing, or physical attacks against our staff, our users, or our providers.
  • Services run by third parties that we do not control.
  • Scanner output with no demonstrated impact, including missing headers, missing cookie flags, and version-disclosure findings.
  • Issues that only affect out-of-date app versions or unsupported browsers.

6. Rules

  • Use your own test accounts. Do not access, modify, or keep data belonging to anyone else.
  • If you do encounter someone else's personal data, stop, do not save it, and tell us in your report.
  • Do not degrade the service for other people.
  • Do not disclose the issue publicly until we have fixed it and agreed a date with you.

7. Recognition

We do not run a paid bug bounty today. We will credit you by name for a valid report if you would like us to, and we will say no thank you politely if you would rather stay anonymous.