Reporting
Security Vulnerabilities
If you've identified a potential vulnerability in our services, please report it by emailing us below.
As the global leader in labor market analytics, we take security seriously and recognize the importance of protecting the privacy and security of our customers and partners. We are committed to identifying, investigating, and responsibly disclosing security vulnerabilities through a coordinated process that helps protect technology users.
Whether you're a Lightcast customer, software developer, or security researcher, your contributions are an important part of that process, and we value your feedback.
After receiving a vulnerability report, we follow a structured process to investigate and resolve the issue.
Please keep details of the reported vulnerability confidential until we have verified and confirmed the issue.
Once the vulnerability is confirmed, we will develop and deploy an appropriate fix. We may also provide recommended mitigations where applicable.
When appropriate, we will disclose the vulnerability along with any available fixes or mitigation guidance.
We will acknowledge the individual(s) who reported the vulnerability or assisted with the resolution, unless they prefer to remain anonymous.
We will endeavor to keep the reporter informed throughout the process.
We will meet or exceed all applicable regulatory and compliance requirements.
We greatly appreciate the efforts of security researchers who responsibly report suspected vulnerabilities. Your partnership helps us strengthen our products and services and better protect our customers. Thank you for working with us.
Reporting a vulnerability
If you've identified a potential security vulnerability or issue with our services, please email us at bugreport@lightcast.io. If you wish to encrypt your report, you can use our OpenPGP public key.