LegalDreams.inThe Modern Legal OS

Responsible Security Disclosure

We take security seriously and welcome reports from researchers who find genuine vulnerabilities. This page explains how to report an issue to us responsibly. See also our Security & Trust Center.

What to Report

Vulnerabilities in legaldreams.in or LegalDreams-operated infrastructure - for example, authentication or authorization flaws, injection vulnerabilities, exposed sensitive data, or misconfigurations that could be exploited.

Safe Testing Expectations

  • Only test against your own accounts or test data - never access, modify, or exfiltrate another person's data.
  • Avoid actions that could degrade service for others, such as high-volume automated scanning.
  • Stop and report as soon as you've confirmed a vulnerability exists - do not go further than necessary to demonstrate impact.
  • Give us a reasonable opportunity to investigate and address an issue before any public disclosure.

Prohibited Testing

  • Denial-of-service testing or any action intended to degrade or disrupt our services.
  • Social engineering, phishing, or physical-security testing against our team.
  • Accessing, modifying, or deleting data that is not yours.
  • Testing against third-party services we use, rather than our own infrastructure.

What to Include in Your Report

A clear description of the issue, steps to reproduce it, the potential impact, and any supporting evidence (screenshots, requests/responses) with sensitive data redacted.

How to Report

Email contact@legaldreams.in with the subject line “Security Disclosure”.

What to Expect

As an early-stage team, we review every report we receive and will acknowledge it. We do not currently publish a fixed numeric response-time SLA; this page will be updated with a formal commitment as our security operations mature. We do not currently offer a paid bug-bounty program.

We ask that you act in good faith and give us a reasonable chance to fix an issue before discussing it publicly. We will not pursue legal action against researchers who follow this policy in good faith.