Level welcomes good-faith reports that help protect customers, Endpoints, and the Services. This Policy explains how to test responsibly, report a suspected vulnerability, and qualify for Level’s safe harbor.
1. How to Report
Email security@level.io with:
- The affected product, hostname, feature, or endpoint.
- Steps to reproduce the issue and the security impact.
- Relevant request and response data, screenshots, logs, or proof-of-concept material.
- Any action already taken to avoid customer impact or further data access.
- A safe way for Level to contact you.
Do not include secrets or unnecessary Personal Information in ordinary email. Ask for a secure transfer method when the report requires sensitive supporting material.
Level will make reasonable efforts to acknowledge a complete report promptly, investigate it, and coordinate updates and disclosure timing with the reporter. Response and remediation time depend on severity, complexity, affected systems, and third-party dependencies. Level does not promise a bounty or payment unless it agrees to one in writing before the work is performed.
2. In-Scope Research
Good-faith research may evaluate Level-owned public websites, applications, APIs, and infrastructure that Level makes available to customers or the public. Research must use accounts, workspaces, Endpoints, and data the researcher owns or is authorized to use.
A researcher should use the minimum testing needed to confirm and explain a vulnerability. If testing unexpectedly reaches another customer’s data, an Endpoint the researcher is not authorized to manage, credentials, or other sensitive information, the researcher must stop, avoid retaining or sharing the information, and report the issue immediately.
3. Out-of-Scope Activity
This Policy does not authorize:
- Access to another customer’s account, data, or Endpoint.
- Social engineering, phishing, physical intrusion, or attacks on Level personnel, customers, or providers.
- Denial of service, resource exhaustion, destructive testing, malware, persistence, or activity that degrades availability.
- Deleting, modifying, encrypting, downloading, or retaining data beyond the minimum needed to demonstrate the issue.
- Automated testing that creates excessive traffic, repeated account creation, spam, or material operational cost.
- Testing a third-party service or integration outside Level’s control without that provider’s authorization.
- Extortion, threats, or disclosure intended to pressure Level or a customer.
4. Safe Harbor
Level considers research conducted in good faith and in accordance with this Policy to be authorized. For that research, Level will not initiate legal action under computer-access or anti-circumvention law and will not submit a Digital Millennium Copyright Act complaint based solely on bypassing a Level technological control to investigate the reported vulnerability.
If Level believes a report does not comply with this Policy, it will make reasonable efforts to explain the concern and allow the researcher to correct an unintentional violation before pursuing a claim, unless immediate action is necessary to protect customers, evidence, safety, or the Services.
This safe harbor applies only to claims Level controls. It does not bind third parties or law enforcement, authorize violations of law, or authorize access to systems, accounts, data, or Endpoints outside the scope above.
5. Coordinated Disclosure
Give Level a reasonable opportunity to investigate and remediate a reported vulnerability before publishing technical details. Level will work in good faith to agree on a disclosure timeline based on severity, exploitability, customer risk, remediation complexity, and whether customers need time to update.
Nothing in this section prohibits a truthful report to a regulator or government authority or another disclosure protected by applicable law.
6. Privacy
Level uses report information to investigate, remediate, communicate about, and document security issues. Level may share it with affected providers, professional advisers, customers, or authorities when reasonably necessary and subject to appropriate safeguards.
A researcher may report anonymously, but anonymity can limit Level’s ability to investigate or provide updates. Level cannot promise confidentiality when disclosure is legally required or necessary to protect an affected person or system.
7. Contact
Questions and reports may be sent to security@level.io.