generated: '2026-08-25' method: searched source: https://www.levitate.ai/vulnerability-disclosure program: Levitate Vulnerability Program (operated by Real Magic) url: https://www.levitate.ai/vulnerability-disclosure http_status: 200 probed: '2026-08-25' report_channel: type: email value: security@levitateapp.com bug_bounty: offered: false statement: "Our program does not currently provide any monetary rewards." security_txt: served: false note: No /.well-known/security.txt on any Levitate host (see well-known/levitate-well-known.yml). in_scope: - Sensitive data exposure — stored XSS, SQL injection and similar - Authentication or session-management issues - Remote code execution - Unique issues that do not fall into an explicit category out_of_scope: - Denial of service (network, resource exhaustion or other) - Issues only present in old browsers, old plugins or end-of-life software - Phishing or social engineering of Real Magic / Levitate employees, users or clients - Disclosure of known public files and non-material information disclosure (e.g. robots.txt) - Any attack that hinges on a user's computer or email account first being compromised researcher_rules: - Do not use a discovered credential or key to test the extent of access it grants. - Do not exploit a discovered SQL injection beyond the initial proof-of-concept. - Excessive exfiltration or downloading of Levitate data, or demanding payment for its destruction, falls outside the program.