Security Vulnerability disclosure policy
Report security issues responsibly.
If you believe you have found a security vulnerability related to lexcyberwall.com, please report it so we can fix it quickly and protect users.
Last updated: 9 April 2026
Vulnerability Disclosure Policy
This policy is intended to make reporting clear, safe, and fast for security researchers and customers.
1. Scope
This policy covers security issues affecting:
- The lexcyberwall.com website and any subdomains that point to this site.
- Public pages, forms, and static assets served from the domain.
If you are unsure whether a target is in-scope, send a note to security@lexcyberwall.com first.
2. How to report
Email us at security@lexcyberwall.com with:
- A clear description of the issue and security impact.
- Steps to reproduce (proof-of-concept where appropriate).
- Affected URLs, parameters, and any relevant request/response details.
- Any mitigation ideas if you have them.
For quick validation, include the smallest possible proof that demonstrates risk. Please avoid sending sensitive personal data. If you need an encrypted channel, ask and we will coordinate.
3. What we ask you to do
- Act in good faith and avoid privacy violations, data destruction, or disruption.
- Do not use social engineering, phishing, or physical attacks.
- Do not run denial-of-service or high-volume automated scanning.
- Do not publicly disclose until we confirm a fix or agree on a timeline.
4. Our response process
- We will acknowledge receipt within 2 business days.
- We will triage and keep you updated on progress where possible.
- We will coordinate on a reasonable disclosure timeline based on severity and fix complexity.
5. Safe harbor
If you follow this policy and act in good faith, we will not pursue legal action against you for authorized testing and disclosure activities related to in-scope targets. This does not cover actions outside the bounds of this policy or illegal activity.
6. Out of scope
The following are typically out of scope:
- Issues in third-party services not controlled by Lex Technologies.
- Missing security headers on non-sensitive public content, where there is no demonstrable impact.
- Best-practice recommendations without a security impact.
- Denial-of-service testing and performance testing.
7. Security contact file
Our machine-readable contact information is available at /.well-known/security.txt.
8. Contact
Lex Technologies
1/108F, Pachapalayam, Coimbatore - 641107, Tamil Nadu, India
Security: security@lexcyberwall.com
General: contact@lexcyberwall.com