generated: '2026-08-25' method: searched source: https://lemfi.com/en-us/legal/vulnerability-disclosure-policy policy_url: https://lemfi.com/en-us/legal/vulnerability-disclosure-policy policy_http_status: 200 program: type: vulnerability-disclosure-program managed_by: Inspectiv submission_url: https://client.inspectiv.com/vdp/lemfi/submit-report submission_issue_contact: programs@inspectiv.com bug_bounty: false bug_bounty_note: >- LemFi's policy states plainly that VDP submissions are not eligible for bounty payment from Inspectiv. Inspectiv runs separate paid bug bounty programs at https://app.inspectiv.com/, but LemFi's published program is disclosure-only. safe_harbor: true safe_harbor_note: >- Good-faith research complying with the policy is treated as "Authorized research" under anti-hacking and anti-circumvention laws, and LemFi commits not to initiate legal action for accidental, good-faith violations. disclosure_window_days: 90 disclosure_window_note: Minimum 90-day window before public announcement. scope: in_scope: - lemfi.com - LemFi Android mobile application - LemFi iOS mobile application - app.lemonade.finance out_of_scope: - Third-party systems and services - Test / staging environments - Corporate IT infrastructure excluded_issue_classes: - Social engineering - Denial of service - Theoretical vulnerabilities without a proof of concept response_commitments: - Respond promptly to reports - Keep reporting researchers informed of progress - Remediate confirmed vulnerabilities in a timely manner - Provide a minimum 90-day disclosure window security_txt: present: false probed: - url: https://lemfi.com/.well-known/security.txt status: 404 note: >- No RFC 9116 security.txt is served. The disclosure policy exists only as an HTML page linked from the site footer, so an automated scanner following the well-known convention will not find it. notes: >- LemFi ships no public API, but it does run a real, named, third-party-managed vulnerability disclosure program with safe harbour and a stated disclosure window — one of only two machine-adjacent trust surfaces this provider publishes.