Vulnerability Disclosure Policy

Littlebird Vulnerability Disclosure Policy (VDP)

Reporting a Vulnerability

If you believe you've found a security vulnerability in Littlebird, please report it to security@littlebird.ai. Include a detailed description, reproduction steps, and any supporting evidence.

Your report must also include a demonstrable proof of concept showing how the vulnerability can be concretely exploited - for example, how it could be used to access or compromise user data, hijack a session, or cause other tangible harm. Reports that only describe theoretical attack scenarios without a working, reproducible PoC will not be eligible for review.

We will acknowledge receipt within 5 business days and aim to provide an initial assessment within 15 business days.

Scope

The following are in scope for this program:

Out of Scope

The following are out of scope and will not be eligible for review:

Ineligible Findings

We follow HackerOne's Core Ineligible Findings as our baseline. In addition, the following are not eligible:

Attacks requiring local device access

Write-only telemetry tokens

Low-impact configuration issues

Other exclusions

Rules of Engagement
Safe Harbor

If you conduct security research in accordance with this policy, we consider your activities to be authorized and will not pursue legal action against you. We ask that you act in good faith, avoid privacy violations, and work with us to resolve issues responsibly.

Recognition

We may offer recognition or compensation for valid, high-impact findings at our discretion. We will work with you directly to determine appropriate acknowledgment.