Lovell Government Services
Vulnerability Disclosure Policy
Partner Portal · Effective July 28, 2026
Purpose
We take the security of the Lovell Partner Portal seriously. This policy describes how security researchers and other parties should report potential vulnerabilities so we can investigate and remediate them through coordinated vulnerability disclosure (CVD).
Scope
This policy applies to the Lovell Partner Portal web application and related services operated by Lovell Government Services for partner onboarding and collaboration. Out-of-scope systems (for example, third-party products we do not operate) should be reported to their respective owners.
How to report
Send reports by email:
Please include enough detail for us to reproduce the issue when possible: affected URL or feature, steps to reproduce, impact assessment, and any proof-of-concept material (without causing harm). Screenshots or logs are welcome. Do not include real partner personal data, credentials, or production secrets in the report body if a redacted example will suffice.
Please do
- Report in good faith and give us a reasonable time to investigate and fix.
- Minimize access to data; stop testing if you encounter personal or sensitive data.
- Keep findings confidential until we have confirmed a fix or agreed otherwise.
- Use only accounts and data you are authorized to use (or that we explicitly provide).
Please do not
- Access, modify, or delete data that is not yours; or exfiltrate production data.
- Execute destructive testing (including denial of service, resource exhaustion, spam, or social engineering of staff or partners).
- Attempt physical attacks, phishing, malware distribution, or attacks against third-party infrastructure we do not control.
- Publicly disclose a vulnerability before we confirm remediation, unless required by law or we agree in writing to a disclosure timeline.
What to expect
- We aim to acknowledge valid reports within a reasonable business timeframe.
- We will work to validate and prioritize findings based on severity and impact.
- We may ask follow-up questions. We will not ask you to share partner credentials or to perform illegal activity.
- We do not currently operate a public bug bounty or guarantee monetary rewards.
Safe harbor
If you conduct research and report in accordance with this policy, we will not pursue legal action for that research activity alone. Activities that violate this policy, applicable law, or that intentionally harm systems or data may not receive that consideration. This statement does not waive rights of third parties.
Machine-readable contact
Security contact metadata is published at /.well-known/security.txt in accordance with RFC 9116.
These materials describe how the Lovell Partner Portal operates. They are not a substitute for advice from your counsel. Questions: lovelltech@lovellgov.com.