Found something? We want to hear it.
Report a security problem and we will work with you in good faith to fix it. This page is the policy that protects you while you do.
How to report
Email support@larssoni.com with the subject line starting SECURITY. Tell us what you found, where, and enough detail for us to reproduce it. If the finding is sensitive, say so in the first line and we will arrange a private channel before you send details.
Safe harbour
We will not pursue legal action against you, and will not treat your testing as a breach of our terms, where you:
- act in good faith and avoid privacy violations, data destruction, and degrading the service for other people;
- only interact with accounts and data you own or have explicit permission to test;
- do not run automated high-volume scanning against production, and do not attempt denial of service;
- give us a reasonable opportunity to fix the issue before disclosing it publicly;
- stop immediately and tell us if you encounter anyone else's data.
Testing within this policy is authorised conduct.
What is in scope
In scope: larssoni.com, the app, the display domains larssonipages.com and larssoni.co, our API, and the auto-update pipeline. We are especially interested in anything touching the display sandbox and its isolation, access to another workspace's data, the setup step's structure-only guarantee, handling of credentials left inside a page, and the gated-sharing email verification flow.
Out of scope: social engineering of people, physical attacks, volumetric denial of service, findings that require a compromised or intercepted victim device, and best-practice observations with no demonstrable impact.
What we promise back
We aim to acknowledge your report within three business days, give you our assessment and a fix timeline, keep you updated as we work, and credit you by name if you would like that once the fix is live. We do not run a paid bounty programme today. We are one person building this — we will be honest with you about timelines rather than silent.