Home / Security
Security

Report security concerns responsibly.

We value clear, good-faith reports that help protect our users, software and infrastructure.

Report suspected vulnerabilities affecting the public Lemoa Connect website, our published applications or official downloads. If you are unsure whether an observation is security-related, send a concise description without attempting intrusive testing.

Include where possible

  • Affected product, version, page, endpoint or feature
  • A clear description of the security impact
  • Reproduction steps using non-sensitive test data
  • Relevant screenshots, request details or logs with secrets removed
  • Whether user or customer information may be affected
  • Your preferred contact details and disclosure expectations
Protect sensitive information. Do not send passwords, private keys, router backups, live customer records or unnecessary personal data by ordinary email. First describe what you have and we will agree on an appropriate transfer method if needed.
Responsible testing

Keep users and live services safe

Please do

  • Use the minimum testing needed to demonstrate the issue
  • Stop if you encounter private or customer information
  • Allow reasonable time for investigation before public disclosure
  • Keep evidence confidential while the report is being reviewed
  • Follow applicable law and platform terms

Please do not

  • Access, change, delete or download data that is not yours
  • Disrupt services, overload systems or degrade availability
  • Use social engineering, phishing or physical intrusion
  • Test customer routers, networks or accounts without written authorisation
  • Demand payment or threaten disclosure
Scope and response

What happens after a report

We review credible reports according to severity, reproducibility and potential user impact. We may request clarification, confirm a fix or advise that the issue belongs to a third-party platform.

This page does not create a bug-bounty programme, promise payment or authorise access to systems. Any testing beyond ordinary use requires explicit written permission. Client-owned infrastructure is never in scope unless its owner has separately authorised the work.

For ordinary product help, installation questions or network troubleshooting, use the Support & FAQ centre.