Power your biggest BFCM yet with a loyalty program Read the NEW Ultimate BFCM Guide

Vulnerability Disclosure Program

Reporting a Vulnerability

At LoyaltyLion, we take security seriously and value the contributions of the security community. If you believe you have discovered a vulnerability in our systems, products, or services, we encourage you to report it responsibly.

Please report any potential vulnerabilities to the following:

When reporting, please provide as much detail as possible, including:

Scope

The following are considered in-scope for our vulnerability disclosure program:

Out-of-scope testing includes (but is not limited to):

Acknowledgement Timelines

We aim to:

Vulnerability Assessment and Prioritization

Upon receiving a report, LoyaltyLion will assess the vulnerability based on several factors, including:

We may adjust remediation priorities accordingly if a vulnerability is determined to be low-risk or not directly exploitable (e.g., protected behind multiple layers of security or unused code paths).

Severity is generally categorised as follows:

Remediation Timelines

We are committed to promptly resolving valid security issues. Our target timelines for remediation are:

In cases where patching is not immediately feasible (e.g., due to the need for substantial application changes), we will:

Public Disclosure Policy

We request that reporters not publicly disclose vulnerabilities until we have had a reasonable opportunity to address the issue. Coordination and mutual agreement on disclosure timelines are encouraged.

We are committed to working with researchers to coordinate public disclosures, ensuring that vulnerabilities are remediated before full details are shared publicly.

Safe Harbor

LoyaltyLion supports responsible security research. We will not pursue legal action against individuals who:

Internal Security Processes

LoyaltyLion employs continuous automated scanning and monitoring, including:

Our goal is to maintain the highest security standards across all environments.