Lendi Group takes cybersecurity seriously. We place emphasis on keeping our online service safe and strive to continuously improve. At the Lendi Group we understand you may choose to provide us feedback to help us improve.
Our Vulnerability Disclosure Program provides security researchers an appropriate process to formally disclose potential vulnerabilities, across our online platforms.
Acceptance Criteria
The Vulnerability Disclosure Program specifically focuses on technical vulnerabilities. You can also refer to our privacy policy and security policy, which outlines the personal information handling practices and contains information on how to raise a privacy request or concern.
We encourage security research, but cannot accept behavior that is destructive, actions that compromise our customers’ personal information or extends into social engineering attacks. Such actions are not considered security research and do not indemnify you from legal liability.
We are also keen to learn of any potential vulnerability, so to help us understand your concerns, it is essential you provide us with sufficient information to allow us to reproduce your finding. Reports should be specific and based on fact.
Submit Your Findings
To submit your findings:
Send an email to VulnerabilityDisclosure@lendi.com.au
Provide sufficient information so that our security team can reproduce your finding. You can help us by listing:
Affected URLs.
Name of account being used for testing.
IP addresses used for testing.
Step-by-step instructions, if the vulnerability is complicated to reproduce.
Whilst submissions can be anonymous, it may help us confirm legitimacy if you provide your real name or link to an online biography.
Hall of Fame
Lendi Group’s policy does not provide financial compensation for the provision of your research findings. Security researchers may however derive value in having their name published online. If you find a meaningful vulnerability then we are happy to add your name here in future updates.
Contributors | Website or Contact |
|---|---|
Aya Atiya | |
Nuno Abreu | @ Shadowstrike |
Meowsint |