Security Policy

LexCompliance Responsible Disclosure Program

Last updated: May 17, 2026

Responsible disclosure program

ForensicCorp SpA operates LexCompliance to the highest security standards. We appreciate security researchers who report vulnerabilities in good faith.

This program covers the complainant portal, management dashboard, and LexCompliance API.

Scope

Complainant portal, management dashboard, public API (app.lexcompliance.cl, api.lexcompliance.cl).

Third-party infrastructure (Supabase, Vercel, Resend, Upstash), DoS attacks, social engineering of ForensicCorp employees.

How to report

Send your report to security@forensic.cl with: vulnerability description, reproduction steps, and estimated impact.

security@forensic.cl

  • Acknowledgment: within 48 hours
  • Triage: within 5 business days
  • Fix published: 90 days (CVSS ≥7.0) · 180 days (CVSS <7.0)

Safe Harbor

Researchers acting in good faith under this policy will not face legal action from ForensicCorp SpA, provided they avoid compromising complainant privacy, disrupting service, or exfiltrating data beyond proof of concept.

Hall of Fame

We'll recognize security researchers here who have contributed responsibly.