generated: '2026-08-04' method: searched probe: true source: https://www.lark.com/responsible-disclosure-policy policy: - https://www.lark.com/responsible-disclosure-policy contact: - security@lark.com - https://support.lark.com/hc/en-us/requests/new?ticket_form_id=4584881616148 bug_bounty: program: OpenBugBounty url: https://www.openbugbounty.org/bugbounty/larkhealth/ reward_minimum: USD 100 reward_form: prepaid Visa gift card first_reporter_only: true geographic_restriction: >- Rewards may not be payable to researchers outside the United States. policy_details: last_updated: '2024-11-18' safe_harbor: true safe_harbor_text: >- "If you have adhered to this Policy, we will not take any legal action against you in regard to the report." proof_of_concept_required: true in_scope: - target: lark.com note: access control and critical web issues only - target: Lark Health Android app - target: Lark Health iOS app - target: careers.lark.com note: write-access vulnerabilities - target: support.lark.com note: Zendesk-related issues out_of_scope: - compromised account access - policy/configuration disagreements - missing security headers - open source library vulnerabilities - third-party vendor vulnerabilities - DoS / DDoS - social engineering - automated scanner output - brute force attempts security_txt: published: false note: >- No /.well-known/security.txt on any lark.com host (RFC 9116 not adopted), even though the disclosure contact security@lark.com is already published on the policy page and in the lark.com CAA iodef record. Publishing security.txt would be a one-file fix. evidence: - source: https://www.lark.com/responsible-disclosure-policy kind: disclosure-policy http_status: 200 - source: https://www.lark.com/security kind: security-page-link http_status: 200 - source: 'CAA record lark.com: 0 iodef "mailto:security@lark.com"' kind: dns x-evidence: fetched: '2026-08-04'