Skip to content
Legasus
POLICY

Responsible Disclosure & Vulnerability Reporting Policy

How to report a suspected security vulnerability to Legasus, what good-faith research looks like, and what to expect after you report.

Effective: Effective April 1, 2026Version: Version 4Jurisdiction: Illinois, USAContact: security@legasus.ai

AIDAN LLC d/b/a Legasus (“Legasus”) values good-faith security research that helps us protect law firms, their clients, and sensitive legal data.

This policy explains how to report suspected security vulnerabilities in Legasus systems.

1. How to Report

Send vulnerability reports to:

security@legasus.ai

Please include, where available:

  • a description of the issue;
  • affected URL, endpoint, feature, or service;
  • steps to reproduce;
  • proof-of-concept material that does not unnecessarily expose sensitive data;
  • potential impact;
  • relevant screenshots or logs;
  • your contact information; and
  • any suggested remediation.

Encrypt sensitive reports where a secure reporting method is made available by Legasus.

2. Good-Faith Research

For purposes of this policy, good-faith research means security testing intended to identify and report a vulnerability while making reasonable efforts to:

  • avoid harm;
  • avoid privacy violations;
  • avoid accessing data beyond what is necessary to demonstrate the issue;
  • avoid service disruption;
  • avoid persistence in Legasus systems;
  • promptly report the issue; and
  • comply with this policy.

3. Authorized Research Conditions

Legasus will generally consider research authorized under this policy when a researcher:

  1. tests only systems reasonably believed to be owned or operated by Legasus and intended to be within the scope of this policy;
  2. uses the research solely to identify or validate a security issue;
  3. does not exploit a vulnerability beyond the minimum reasonably necessary to demonstrate it;
  4. stops testing and reports immediately if Customer Data, privileged information, PHI, credentials, secrets, or other sensitive information is encountered;
  5. does not download, retain, alter, destroy, or disclose Customer Data;
  6. does not conduct denial-of-service testing;
  7. does not use social engineering, phishing, physical intrusion, threats, extortion, or coercion;
  8. does not test third-party systems without authorization from that third party;
  9. does not use compromised credentials or purchase stolen credentials;
  10. does not create persistence or backdoors;
  11. does not publicly disclose the vulnerability before Legasus has had a reasonable opportunity to investigate and remediate; and
  12. complies with applicable law.

4. Out-of-Scope Activities

The following are not authorized under this policy unless Legasus gives prior written permission:

  • denial-of-service or load testing;
  • destructive testing;
  • physical security testing;
  • social engineering;
  • phishing or credential harvesting;
  • spam;
  • testing employees' personal accounts or devices;
  • testing a third-party provider's infrastructure;
  • automated scanning at a volume that materially affects service;
  • accessing another Customer's data beyond the absolute minimum needed to recognize the exposure;
  • exporting real Customer Data;
  • modifying or deleting Customer Data;
  • persistence or lateral movement after confirming a vulnerability; or
  • demanding payment or threatening disclosure as a condition of reporting.

5. Sensitive Data

If you encounter Customer Data or other sensitive information:

  1. stop accessing the information;
  2. do not copy, download, photograph, transmit, or retain it beyond what is strictly necessary to document the vulnerability;
  3. do not contact the affected Customer directly unless Legasus authorizes it or law requires it; and
  4. report the issue to security@legasus.ai promptly.

6. What You Can Expect From Legasus

For reports that appear credible and in scope, Legasus will use reasonable efforts to:

  • acknowledge receipt;
  • triage the report;
  • investigate and prioritize based on risk;
  • communicate with the reporter where additional information is needed; and
  • remediate confirmed issues according to risk and operational considerations.

Legasus does not promise a specific response or remediation timeframe through this public policy unless separately stated.

7. Safe-Harbor Intent

When a researcher makes a good-faith effort to comply with this policy and applicable law, Legasus's intent is not to pursue legal action against the researcher solely for the authorized security research described here.

This statement is limited to Legasus's own rights and cannot bind third parties, law enforcement, regulators, or other rights holders. It does not authorize conduct prohibited by law.

If you are uncertain whether testing is permitted, contact security@legasus.ai before proceeding.

8. Rewards

Unless Legasus separately announces a bug-bounty program or reward in writing, this policy does not create a right to payment, bounty, credit, employment, or other compensation.

9. Public Disclosure

Do not publicly disclose a vulnerability, exploit, Customer impact, or sensitive technical details until Legasus confirms that coordinated disclosure is appropriate or sufficient remediation time has passed as mutually agreed.

10. Security Incidents Affecting a Customer

Customers reporting suspected compromise of their own account should contact security@legasus.ai and support@legasus.ai and should not use this policy as a substitute for the Security Addendum or contractual incident process.

11. Contact

Security: security@legasus.ai
Legal: legal@legasus.ai