Find a bug. Get honor.
Security research keeps the platform honest. If you find a vulnerability in a LILY service or in the infrastructure that hosts user-deployed applications, tell us.
Valid findings earn platform credits and a place on the Wall of Fame. Reports are filed inside the platform, so sign in first.
The Scope.
In scope
*.lilylabs.io
every LILY service: platform, auth, docs, this site
*.lilylabs.app
the hosting infrastructure behind user-deployed services
Out of scope
- Third-party services we integrate with
- Social engineering or physical attacks
- Denial-of-service or volumetric attacks
- Vulnerabilities in the code of user-deployed services themselves
Not considered a vulnerability
- Missing security headers without demonstrated impact
- Email spoofing, SPF, DMARC or DKIM issues
- Self-XSS
- Clickjacking on pages without sensitive actions
- Vulnerabilities requiring physical access or rooted devices
- Reports from automated scanners without manual validation
- Best-practice suggestions without security impact
- DoS, DDoS or rate-limiting issues
- Issues only affecting outdated browsers (more than two versions old)
Paid in platform credits.
Rewards are issued as credits on your LILY account. Wall of Fame recognition is reserved for High and Critical reports. The final tier depends on impact, report quality and exploit reliability.
| Severity | Reward | Examples |
|---|---|---|
| Critical | 1 year Pro plan, Wall of Fame, handwritten letter from the founders | Remote code execution, full account takeover, mass data exposure |
| High | 6 months Pro plan, Wall of Fame | Privilege escalation, sensitive data leak, authentication bypass |
| Medium | 3 months Pro plan | Limited information disclosure, stored XSS, CSRF on sensitive actions |
| Low | 1 month Pro plan | Reflected XSS, minor information leak, security best-practice gaps |
Rules of Engagement.
- 01Test only against your own accounts and assets you control.
- 02Do not access, modify or destroy other users' data.
- 03Provide clear reproduction steps. No proof of exploit beyond what is necessary.
- 04Give us reasonable time to fix before public disclosure, 90 days by default.
- 05The first reporter of a unique, valid finding gets the reward.
Safe Harbor.
We consider security research conducted in accordance with this policy as authorized under sections 202a to 202c of the German Criminal Code. We will not pursue civil or criminal action against researchers who make a good-faith effort to comply with this policy, avoid privacy violations and data exfiltration beyond what is necessary to demonstrate the issue, and report findings promptly without disclosing them publicly before we have had a reasonable chance to respond.
If a third party initiates legal action against you for activities conducted under this policy, we will make it known that your actions were authorized.
The researchers who keep LILY secure.
The roster goes live once the first valid High or Critical findings are triaged. Until then, the slots are yours to claim.
Reports are filed inside the platform.
Sign in to the platform with Google or GitHub and open Feedback & Reports from the sidebar, or use the link below, which opens the form directly. Mark the report as a security issue and include reproduction steps. We confirm receipt and keep you updated in the same thread.
If you cannot sign in, email [email protected].
Step into the world after the cloud.
Start for free, integrate in minutes, and scale when you need to.
What is coming after the cloud
LILY Labs GmbH, Maudacherstraße 45, 67065 Ludwigshafen am Rhein
Amtsgericht Ludwigshafen am Rhein, HRB 70791
© 2026 LILY Labs GmbH. All rights reserved.