Security disclosure program

Find a bug. Get honor.

Security research keeps the platform honest. If you find a vulnerability in a LILY service or in the infrastructure that hosts user-deployed applications, tell us.

Valid findings earn platform credits and a place on the Wall of Fame. Reports are filed inside the platform, so sign in first.

Scope

The Scope.

In scope

  • *.lilylabs.io

    every LILY service: platform, auth, docs, this site

  • *.lilylabs.app

    the hosting infrastructure behind user-deployed services

Out of scope

  • Third-party services we integrate with
  • Social engineering or physical attacks
  • Denial-of-service or volumetric attacks
  • Vulnerabilities in the code of user-deployed services themselves

Not considered a vulnerability

  • Missing security headers without demonstrated impact
  • Email spoofing, SPF, DMARC or DKIM issues
  • Self-XSS
  • Clickjacking on pages without sensitive actions
  • Vulnerabilities requiring physical access or rooted devices
  • Reports from automated scanners without manual validation
  • Best-practice suggestions without security impact
  • DoS, DDoS or rate-limiting issues
  • Issues only affecting outdated browsers (more than two versions old)
Rewards

Paid in platform credits.

Rewards are issued as credits on your LILY account. Wall of Fame recognition is reserved for High and Critical reports. The final tier depends on impact, report quality and exploit reliability.

SeverityReward
Critical1 year Pro plan, Wall of Fame, handwritten letter from the founders
High6 months Pro plan, Wall of Fame
Medium3 months Pro plan
Low1 month Pro plan
Rules of engagement

Rules of Engagement.

  1. 01Test only against your own accounts and assets you control.
  2. 02Do not access, modify or destroy other users' data.
  3. 03Provide clear reproduction steps. No proof of exploit beyond what is necessary.
  4. 04Give us reasonable time to fix before public disclosure, 90 days by default.
  5. 05The first reporter of a unique, valid finding gets the reward.
Safe harbor

Safe Harbor.

We consider security research conducted in accordance with this policy as authorized under sections 202a to 202c of the German Criminal Code. We will not pursue civil or criminal action against researchers who make a good-faith effort to comply with this policy, avoid privacy violations and data exfiltration beyond what is necessary to demonstrate the issue, and report findings promptly without disclosing them publicly before we have had a reasonable chance to respond.

If a third party initiates legal action against you for activities conducted under this policy, we will make it known that your actions were authorized.

Wall of Fame

The researchers who keep LILY secure.

The roster goes live once the first valid High or Critical findings are triaged. Until then, the slots are yours to claim.

slot 01?vacant
slot 02?vacant
slot 03?vacant
slot 04?vacant
slot 05?vacant
slot 06?vacant
How to report

Reports are filed inside the platform.

Sign in to the platform with Google or GitHub and open Feedback & Reports from the sidebar, or use the link below, which opens the form directly. Mark the report as a security issue and include reproduction steps. We confirm receipt and keep you updated in the same thread.

If you cannot sign in, email [email protected].

Step into the world after the cloud.
Start for free, integrate in minutes, and scale when you need to.

Start for free
LILY

What is coming after the cloud

LILY Labs GmbH, Maudacherstraße 45, 67065 Ludwigshafen am Rhein
Amtsgericht Ludwigshafen am Rhein, HRB 70791

© 2026 LILY Labs GmbH. All rights reserved.