Security & Vulnerability Disclosure
Last updated: May 5, 2026
Litchoo is committed to ensuring the safety, confidentiality, and integrity of our users' data. We value the input and efforts of security researchers, users, and the wider community to help us maintain a secure platform.
1. Reporting Vulnerabilities
If you believe you have discovered a security vulnerability or security issue affecting Litchoo or any connected service integrations, please report it to us immediately.
To report a vulnerability, please email us directly at litchoofficial@gmail.com with the subject line"Security Vulnerability Report".
2. Submission Guidelines
When submitting a report, please include as much detail as possible to help us reproduce and verify the issue:
- A clear description of the vulnerability and its potential impact.
- Detailed, step-by-step instructions or proof-of-concept (PoC) code to reproduce the issue.
- The specific URL, API endpoint, or component affected.
- Any details regarding your operating environment, browser version, or request payloads.
3. Responsible Disclosure & Safe Harbor
To protect our users and system integrity, we request that you:
- Do not exploit the vulnerability to view, modify, delete, or harvest user data.
- Do not perform denial-of-service (DoS) attacks or cause degradation to platform performance.
- Give us a reasonable amount of time to resolve the issue before disclosing it publicly.
- Avoid social engineering, phishing, or physical security attacks against Litchoo employees or infrastructure.
If you act in good faith and follow these guidelines, we will not pursue legal action or suspend your access to our services.
4. Our Response Process
We treat security submissions with high priority:
- We will acknowledge receipt of your report within 3 business days.
- We will work diligently to investigate, verify, and remediate the issue.
- We will keep you informed of our progress and resolution timeline.