Responsible Disclosure Policy


To provide researchers with a clear and easy path to alert your security team of a potential vulnerability. It defines what properties are in or out of bounds, what types of vulnerabilities should and shouldn’t be reported, and provides the disclosure method.

Disclosure Policy

If you believe you’ve discovered a potential vulnerability, please let us know by emailing us at We will acknowledge your email within one week.

Provide us with a reasonable amount of time to resolve the issue before disclosing it to the public or a third party. We aim to resolve critical issues within ten business days of disclosure.

Make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Leapfin service. Please only interact with accounts you own or for which you have explicit permission from the account holder.


While researching, we’d like you to refrain from:

  • Distributed Denial of Service (DDoS)
  • Spamming
  • Social engineering or phishing of Leapfin employees or contractors
  • Any attacks against Leapfin’s physical property or data centers

This policy applies to the Leapfin Application hosted at and to any other subdomains or services associated with the Leapfin App. We do not accept reports for vulnerabilities solely affecting our marketing website (, which contains no sensitive data.

Thank you for helping to keep Leapfin and our users safe!


We may revise these guidelines from time to time. The most current version of the guidelines will be available at


Leapfin is always open to feedback, questions, and suggestions. If you would like to talk to us, please feel free to email us at