Security
Vulnerability disclosure policy
Reporting a vulnerability
If you believe you have found a security vulnerability in layerone.am, the panel console at panel.layerone.am, or the LayerOne platform software, email info@layerone.am. Include enough detail to reproduce the issue. Encrypted reporting is available on request.
What to expect
We aim to acknowledge reports within five business days and to keep you informed while we investigate and fix confirmed issues. We support good-faith security research and will not pursue legal action for research conducted in line with this policy.
Guidelines
- Do not disrupt service or degrade availability — no volumetric or denial-of-service testing.
- Do not access, modify, or delete data that is not your own; test only against accounts and tenants you control.
- Give us reasonable time to remediate before publishing details.
Scope
This website and the panel console it links to. Platform deployments operated by our customers are covered by the respective operator’s own disclosure process.