Vulnerability Disclosure Policy
Last updated: October 4, 2026
We welcome reports from security researchers. If you think you have found a vulnerability in one of our products, please tell us. We read every report, we answer within 24 hours on any day of the week, and we will not take legal action against research done in good faith under this policy.
1. Scope
In scope:
- CogniRunner for Jira Cloud (Atlassian Marketplace app key
com.leanzero.jira.cognirunner). - Sentinel Vault for Confluence Cloud (
com.leanzero.confluence.sentinelvault). - LeanZero Management for Jira Cloud (
com.leanzero.jira.leanzeromanagement). - The website leanzero.net and its API routes.
- The LeanZero Link sign-in service and its network coordination server.
- Our hosted MCP Doc Processor and MCP Web Search demo servers.
- Goose Swarm, our desktop app.
The Link and MCP services run on a small server of ours: use one account or demo key of your own, keep automated requests slow, and do not try to reach other users’ data or documents beyond what proves the issue.
Out of scope:
- Atlassian’s own products and the Forge platform. Report those to Atlassian’s bug bounty.
- Third-party services we use, such as AI providers, email delivery or analytics. Report those to the service.
- Denial of service, load or volumetric testing, and spam.
- Social engineering or phishing of our team or our customers, and physical attacks.
- Any Atlassian site, account or data that is not yours, including our customers’ sites.
- Scanner output with no demonstrated impact, and missing best-practice headers with no exploit.
2. How to Test
- Install our apps from the Atlassian Marketplace on your own Atlassian Cloud site, for example a free developer site. Paid apps can be installed on a free trial.
- Only use accounts and data that you own or are allowed to use.
- If you reach data that belongs to someone else, stop, do not keep a copy, and tell us.
- Do not degrade the service for others. Rate-limit automated tools.
- The forms on leanzero.net send real emails. Keep submissions to the minimum you need.
3. How to Report
Use the Report a security vulnerability form on our support portal (only you and our team can see the request), or email office@leanzero.net with “Security” in the subject line. Please include:
- The product (and version, if you know it) and the affected URL, module or API.
- Steps to reproduce, and a proof of concept if you have one.
- The impact as you see it.
- How you would like to be credited, if at all.
You can also report through Atlassian, as its Marketplace vulnerability disclosure page describes: on its Bugcrowd program with the “Third Party Marketplace Apps” target, or by email to security@atlassian.com. Atlassian forwards such reports to the app’s partner.
4. What You Can Expect
- Acknowledgement within 24 hours, any day of the week, weekends and public holidays included.
- A severity assessment (CVSS) and our plan, as soon as we have reproduced the issue.
- Fixes in our cloud apps, counted from when the issue is reported or triaged, within the timelines of Atlassian’s Security Bug Fix Policy: critical within 10 days, high within 4 weeks, medium within 12 weeks and low within 25 weeks.
- Updates while we work on it, and a note when the fix ships.
- Credit on this page once the issue is fixed, if you want it.
Please give us a reasonable time to fix the issue before you disclose it publicly. We will agree a date with you. If we have not agreed one, 90 days from your report is the default.
5. Safe Harbor
If you make a good-faith effort to follow this policy during your research:
- We consider your research authorized, including for the purposes of anti-hacking laws such as Article 360 of the Romanian Criminal Code, and we will not bring or support legal action against you for it.
- Research under this policy is allowed despite the restrictions in section 2.2 of our Terms of Service (for example on reverse engineering), to the extent the research needs.
- If a third party brings legal action against you for research that followed this policy, we will make it known that your activities were authorized by us.
We can only authorize testing of our own products. We cannot authorize testing of Atlassian’s systems or of anyone else’s. Safe harbor does not cover accessing, changing or keeping other people’s data beyond what is needed to show the issue, denial of service, social engineering, or testing systems that are not ours.
6. Rewards
We do not pay bounties at the moment. We intend to join Atlassian’s Marketplace Security Bug Bounty Program; when we do, this page will link to it. Until then, we credit every valid report publicly, with your permission.
7. Acknowledgments
Researchers who report valid issues are listed here, with their permission, once the fix has shipped.
Machine-readable contact: /.well-known/security.txt. See also: Trust Center | Support SLA | Privacy Policy