Responsible Disclosure Policy
Lifetime Domain welcomes security researchers to help us maintain the security of our platform. We appreciate your efforts to responsibly disclose your findings.
Scope
This policy applies to any security vulnerabilities found in:
- lifetime-domain.com and all subdomains
- Our domain marketplace platform
- Payment processing systems
- User authentication and account management
What to Report
We're interested in any security issues, including but not limited to:
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- SQL Injection
- Authentication and authorization flaws
- Server-side code execution
- Sensitive data exposure
- Security misconfigurations
Safe Harbor
When conducting security research according to this policy, we consider it authorized conduct and will not pursue legal action. We ask that you:
- Make a good faith effort to avoid privacy violations and disruptions
- Only interact with accounts you own or with explicit permission
- Do not perform DoS/DDoS attacks
- Do not exploit the vulnerability beyond necessary verification
Response
We commit to:
- Respond to your report within 48 hours
- Keep you informed about our progress
- Credit you for your discovery (unless you prefer to remain anonymous)