generated: '2026-08-25' method: searched source: https://www.lvt.com/legal/vdp status: published policy_url: https://www.lvt.com/legal/vdp policy_title: Vulnerability Disclosure Policy http_status: 200 security_txt: absent security_txt_probes: - url: https://www.lvt.com/.well-known/security.txt status: 404 - url: https://api.lvt.com/.well-known/security.txt status: 404 - url: https://lvt.com/.well-known/security.txt status: 404 contact: email: security@lvt.com method: 'Email security@lvt.com with the address tied to your Bugcrowd researcher account to request an invite.' bug_bounty: platform: Bugcrowd platform_url: https://bugcrowd.com/ program_type: private, invite-only public_program_page: false rewards: 'Managed inside the Bugcrowd platform; scope and reward structure are not published publicly.' intake_flow: - Hold an active researcher account at Bugcrowd.com - Email security@lvt.com requesting an invite - Include the email address associated with your Bugcrowd account - LVT's security team reviews the request and issues an invitation to the private program commitments: - Timely response — acknowledgement of invite requests and findings - Collaboration to understand and validate reports - 'Safe harbour: LVT will not take legal action against researchers who report in good faith and follow the Bugcrowd program guidelines' safe_harbour: true safe_harbour_guidelines_excerpt: >- Researchers are asked to avoid privacy violations, degradation of user experience, and disruption (text truncated on the published page as rendered). note: >- LVT runs a genuine, documented disclosure programme with named safe harbour and a real intake address, but it is discoverable only by finding /legal/vdp — there is no /.well-known/security.txt on any LVT host, so an automated scanner or an agent following RFC 9116 will not find it. Publishing a security.txt pointing at https://www.lvt.com/legal/vdp and security@lvt.com would be a one-file fix.