generated: '2026-08-13' method: searched probe: true source: https://hackerone.com/lemlist policy: - https://hackerone.com/lemlist contact: [] program: platform: HackerOne handle: lemlist name: lemlist Vulnerability Disclosure Program type: vulnerability-disclosure state: public_mode bounty: unknown evidence: - source: https://hackerone.com/lemlist kind: bug-bounty-platform http_status: 200 detail: 'page title "lemlist - Vulnerability Disclosure Program | HackerOne"' - source: https://hackerone.com/graphql kind: platform-api http_status: 200 detail: 'query team(handle:"lemlist") returned {"handle":"lemlist","name":"lemlist","state":"public_mode"} — the program exists and is public' gaps: - item: security.txt detail: >- No RFC 9116 /.well-known/security.txt on any lemlist host. www.lemlist.com and developer.lemlist.com return 404; api.lemlist.com and app.lemlist.com return a soft-200 HTML application shell. Publishing one that points at the HackerOne program would make this program machine-discoverable. - item: on-site disclosure page detail: >- /security, /legal/security and /responsible-disclosure on www.lemlist.com all return 404 — the program is only discoverable on HackerOne.