Trust Center
Report a security issue
Report a suspected Lithi security issue with useful context, safe testing boundaries, and privacy guidance for your submission.
On this page
If you suspect a security issue in a Lithi-controlled surface, send a private report to the Trust Center. Include the affected product or route, the smallest safe reproduction, the observed impact, and a reply contact. Test only systems and accounts you are authorized to use, then stop when the behavior is clear enough to describe.
Include the useful minimum
A short, focused report helps the security team understand what happened without creating new exposure. Include:
- Affected surface: Name the product area, route, interface, or documented behavior. Add a stable URL or plain description when available.
- Safe reproduction: List the least invasive actions that show the behavior. Use an account you are authorized to test.
- Observed impact: Explain what you saw and why it may matter. Label any suspected effect that you could not confirm.
- Reply contact: Give a safe way to answer questions. Do not use a password, token, customer record, or other secret as contact detail.
Screenshots, timestamps, and sanitized excerpts can help when they contain no sensitive information. You do not need to provide a polished exploit demonstration. If a result is inconsistent, describe what changed and which step remains uncertain.
Stay within safe testing
Do not access another person’s account or data. Do not guess or reuse credentials, bypass a permission boundary, alter or export data, disrupt availability, send unsolicited messages, or change service settings. Do not create persistence or continue testing after the concern is clear.
If you encounter personal information, customer content, or a secret, stop immediately. Preserve only the minimum detail needed to identify the issue, redact the rest, and keep the report private while it is assessed. Share follow-up material only through the private reporting channel.
This guide does not promise an acknowledgement time, remediation timeline, reward, legal protection, or particular outcome. It also does not authorize testing outside the system, account, and behavior you describe.
Related links
- Review Compute security for public security boundaries and limits.
- Read the security disclosure page for the reporting policy and response boundary.
Primary action
Email security@lithi.ai with the affected surface, safe reproduction, observed impact, and a safe reply contact. Keep secrets, customer data, and unrelated personal information out of the message.