Responsible Disclosure
This policy defines how researchers will be able to coordinate good-faith reports about official Liiiraa Boost assets after the designated contact completes operational preflight.
Designated contact: security@liiiraa.com. Coordinated intake will open only after preflight confirms that the address exists, is authenticated, and is monitored.
- Current version
2.0.0- Effective date
- Contact status
- Preflight required
Scope
- Liiiraa Boost-controlled domains and subdomains that link directly to this policy from their footer
- The Windows application, installer, updater, manifests, and official artifacts actually published through the download channel
- Reproducible authentication, authorization, privacy, integrity, update, licensing, or restoration flaws in those assets, demonstrated with minimum necessary proof
Prohibited content
- Denial of service, destructive or high-volume automated testing, malware, ransomware, persistence, social engineering, phishing, spam, match interference, or changing and deleting data
- Access beyond the minimum needed to prove the flaw, lateral movement, attempts against another person's account, or submission of passwords, tokens, payment data, personal files, or unrelated diagnostics
- Testing third-party services, providers, users, or assets outside scope; exploitation for personal benefit; extortion; or public disclosure before responsible coordination
Expected response
After preflight confirms that security@liiiraa.com exists, is authenticated, and is monitored, the designated contact may receive the asset and version, preconditions, reproducible steps, impact, minimum proof without secrets, and a return address chosen by the researcher. The process will then acknowledge usable reports, triage scope and risk, and provide updates when there is a material change. Complexity, impact, and deployment safety will determine timing; there is no promise of a fixed date and no bounty, reward, or payment is offered. Good-faith research will remain authorized only within this scope and will not bind third parties or cover independent unlawful conduct. Disclosure must be coordinated until a fix exists or a responsible window is agreed.
Version history
1.0.0Initial reporting scope and coordination contact.
1.1.0First detailed description of minimum proof, prohibited conduct, and response steps.
2.0.0Final pre-launch policy with verifiable scope, limited good-faith authorization, coordination, data protection, and no bounty or SLA.