Vulnerability disclosure
Last updated 23 August 2026
If you find a security issue in Lilla, tell us privately before you tell anyone else. We will work with you to understand the report and fix what we can.
Contact
Email lilla@genzis.net or support@lilla.cm with the subject line starting SECURITY. This file is also advertised at /.well-known/security.txt.
What to include
- The affected host and path (for example
lilla.genzis.netor the API). - What you did, what you expected, and what happened.
- Impact: whose data or which event-day flow is at risk.
- A proof of concept that does not keep access, exfiltrate data, or disrupt a live event.
Scope
- In scope:
lilla.genzis.net,api.lilla.genzis.net, and the Lilla application behind them. - Out of scope: denial-of-service, physical access, social engineering of staff or organizers, and issues that only affect a local or staging copy you run yourself.
Our side of the bargain
- We aim to acknowledge a good-faith report within three business days.
- We will not pursue legal action against researchers who stay in scope and do not disrupt events or access other people's data beyond what is needed to demonstrate the issue.
- There is no paid bounty in V1. We will credit you on request once a fix is live, unless you prefer to stay anonymous.
Related
Event and content reports (scam listings, abuse) go through Safety & reporting, not this inbox.
Questions: support@lilla.cm