Responsible disclosure
If you find a security issue in LeadRadar, we want to hear from you, and we will not take legal action against good-faith research that follows these rules.
How to report
E-mail security@leadradar.example with steps to reproduce, affected URL or component, and impact. Encrypt sensitive reports with our PGP key (published on this page after launch). We acknowledge within 2 working days and give a remediation estimate within 10.
Rules
- Test only against accounts you own or demo tenants we provide; never access another tenant's data.
- No denial of service, social engineering, physical attacks or spam.
- Stop and report as soon as you can demonstrate the issue; do not exfiltrate data.
- Give us 90 days before public disclosure, or longer if we agree a date together.
In scope
The platform, its API, the worker and this website. Out of scope: third-party providers listed as sub-processors (report to them), rate-limit findings without impact, and issues in the fictional demo data.
Recognition
We credit reporters who wish to be named on this page. A paid bounty programme is planned after the pilot.
Items highlighted like this are filled in per customer or before launch. We describe controls we operate; we do not present GDPR compliance, AI Act conformity or ISO certification as achieved results until verified.