generated: '2026-08-01' method: searched probe: true source: https://lucid.co/security policy: - https://lucid.co/security contact: - security@lucid.co bug_bounty: runs_program: true platform: HackerOne public_program_url: null invite_only: true enrollment: >- "Lucid enables third-party researchers to find and report security bugs in our products through our bug bounty program, hosted by HackerOne. If you would like to join our program, please send your HackerOne username to security@lucid.co." bounty_note: >- "If you believe you have found a security bug in our products, you are also welcome to send the details directly to security@lucid.co rather than making your report through HackerOne. However, bounties will only be awarded through our HackerOne program." security_txt: present: false probed: - {url: 'https://lucid.co/.well-known/security.txt', status: 404} - {url: 'https://lucid.app/.well-known/security.txt', status: 404} - {url: 'https://api.lucid.co/.well-known/security.txt', status: 404} - {url: 'https://developer.lucid.co/.well-known/security.txt', status: 404} gap: >- Lucid runs a real disclosure program but publishes no RFC 9116 security.txt on any host, so the program is not machine-discoverable. evidence: - source: https://lucid.co/security kind: public security page — bug bounty section + FAQ ("Does Lucid have a bug bounty program?") http_status: 200 - source: https://trust.lucid.co/ kind: SafeBase trust center report_vulnerability_url = mailto:security@lucid.co http_status: 200 x-evidence: fetched: '2026-08-01' urls: - https://lucid.co/security - https://trust.lucid.co/