Security
Vulnerability disclosure
We take the security of Landed seriously. If you believe you have found a vulnerability in our website, APIs, or desktop application, please tell us so we can fix it.
How to report
Email landed.support@gmail.com with the subject line “Security vulnerability.” Include enough detail for us to reproduce the issue (steps, affected URLs or app version, and impact). Do not include passwords, payment card data, or other secrets belonging to third parties.
Our commitments
- We will acknowledge valid reports within a reasonable time.
- We ask that you give us a reasonable opportunity to remediate before any public disclosure.
- Do not access, modify, or delete data that is not yours; do not perform denial-of-service testing; and do not exploit an issue beyond what is needed to demonstrate it.
Scope
In scope: https://landed-ai.com, authenticated Landed APIs, and the official Landed desktop application. Out of scope: third-party services we integrate with (report those to the provider), social engineering, and physical attacks.
Legal identity and operator details: Legal Notice.