Skip to main content
Liiiraa Boost
Menu
Security

Responsible Disclosure

This policy defines how researchers will be able to coordinate good-faith reports about official Liiiraa Boost assets after the designated contact completes operational preflight.

Designated contact: security@liiiraa.com. Coordinated intake will open only after preflight confirms that the address exists, is authenticated, and is monitored.

Current version
2.0.0
Effective date
Contact status
Preflight required

Scope

  • Liiiraa Boost-controlled domains and subdomains that link directly to this policy from their footer
  • The Windows application, installer, updater, manifests, and official artifacts actually published through the download channel
  • Reproducible authentication, authorization, privacy, integrity, update, licensing, or restoration flaws in those assets, demonstrated with minimum necessary proof

Prohibited content

  • Denial of service, destructive or high-volume automated testing, malware, ransomware, persistence, social engineering, phishing, spam, match interference, or changing and deleting data
  • Access beyond the minimum needed to prove the flaw, lateral movement, attempts against another person's account, or submission of passwords, tokens, payment data, personal files, or unrelated diagnostics
  • Testing third-party services, providers, users, or assets outside scope; exploitation for personal benefit; extortion; or public disclosure before responsible coordination

Expected response

After preflight confirms that security@liiiraa.com exists, is authenticated, and is monitored, the designated contact may receive the asset and version, preconditions, reproducible steps, impact, minimum proof without secrets, and a return address chosen by the researcher. The process will then acknowledge usable reports, triage scope and risk, and provide updates when there is a material change. Complexity, impact, and deployment safety will determine timing; there is no promise of a fixed date and no bounty, reward, or payment is offered. Good-faith research will remain authorized only within this scope and will not bind third parties or cover independent unlawful conduct. Disclosure must be coordinated until a fix exists or a responsible window is agreed.

Version history

  1. 1.0.0

    Initial reporting scope and coordination contact.

  2. 1.1.0

    First detailed description of minimum proof, prohibited conduct, and response steps.

  3. 2.0.0

    Final pre-launch policy with verifiable scope, limited good-faith authorization, coordination, data protection, and no bounty or SLA.