Scope
This policy applies to security vulnerabilities affecting LawKade-operated systems, including:
- lawkadesecurity.com and all subdomains
- The ARGUS platform and customer portal
- LawKade API infrastructure
This policy does not cover vulnerabilities in third-party software or services that LawKade uses but does not operate. Those should be reported directly to the relevant vendor.
How to report
To report a security vulnerability in LawKade systems, use our contact form with the subject line Security Vulnerability Report.
Include in your report:
- Description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Affected URL, endpoint, or system
- Any proof-of-concept code or screenshots (do not include real user data)
- Your contact information for follow-up
Our commitments
- We will acknowledge receipt of your report within 5 business days
- We will investigate and provide an initial assessment of the issue
- We will notify you when the issue is resolved
- We will not take legal action against researchers who report issues in good faith following this policy
- We will credit researchers who report valid issues if they request attribution
Expectations for reporters
To qualify for good-faith treatment under this policy, reporters must:
- Limit testing to the minimum necessary to confirm the vulnerability
- Not access, exfiltrate, or retain customer data encountered during testing
- Not disrupt LawKade services or perform denial-of-service testing
- Not share vulnerability details publicly before the issue is resolved or 90 days have passed
- Not use the vulnerability for personal gain
Bug bounty
LawKade does not currently operate a paid bug bounty program. We do not offer monetary compensation for vulnerability reports. We will provide public or private credit to reporters who request it upon resolution of a valid finding.