Reporting Vulnerabilities

Please do not open public issues for security vulnerabilities. Report issues privately so we can triage and respond without exposing users to additional risk.

Response targets Initial acknowledgment within 72 hours, triage within 7 days, and remediation timing based on severity and exploitability.

Secret Handling

We avoid committing credentials, API keys, or tokens to the repository and expect operators to use environment variables for deployment secrets.

Defense Controls

Lyralink uses HTTPS, session controls, rate limiting, verification safeguards, and logged security events to protect account access and platform integrity.

Security-sensitive actions are gated by server-side checks, and operator workflows are audited where appropriate.

Contact

Lyralink Security

LyralinkAI · security@lyralinkai.com

Email Security

See also Status, API Docs, Privacy Policy, and Terms of Service.