Security & Vulnerability Reporting
Report a suspected LifeOrg vulnerability privately to security@lifeorg.app. If the matter concerns account access, support@lifeorg.app can also help. A report should contain enough information to investigate without exposing other users or unnecessary personal data.
1. Scope of our public security statements
We are responsible for maintaining technical and organizational measures appropriate to the personal data, processing and risks. This includes managing access, authentication, secrets, storage permissions, operational visibility and the response to security concerns.
Different features have different audiences: private account material and approved public place photos must not be confused. Authorization and storage access have to reflect the intended audience. Do not submit confidential information to a public library or use public contributions to report a vulnerability.
Security controls reduce risk but do not make any system immune from an incident. We do not offer an end-to-end encryption or formal security-certification claim through this page. If a particular assurance is important to your intended use, contact security@lifeorg.app for information before sharing sensitive material.
2. How to make a useful private report
We review reports and communicate as appropriate to the investigation. A report does not create a bounty entitlement, paid engagement or guaranteed resolution date. Do not assume a message has been received if delivery fails; use the operator’s postal contact or another published LifeOrg contact route.
- Identify the affected LifeOrg domain, screen, component or app version and describe the unexpected behavior and likely impact.
- Provide minimal reproduction steps using your own test account and, where helpful, a redacted screenshot or example request.
- Include when you observed the issue, whether it remains reproducible and how we can contact you. State whether sensitive information may have been exposed without sending that information itself.
- Remove passwords, tokens, session cookies, private keys, personal records and third-party data from your report. If sensitive evidence is essential, ask us to arrange an appropriate exchange method before sending it.
3. Boundaries for testing and coordinated disclosure
Do not access, alter, copy or delete another user’s data; obtain credentials; attempt persistence; disrupt availability; conduct denial-of-service testing; or use social engineering against users, personnel or providers. If you encounter someone else’s information, stop, avoid retaining it and report the minimum necessary facts.
This reporting policy does not authorize intrusive testing of production systems or third-party infrastructure. Request written scope and permission before testing beyond normal use of your own account. Applicable law and the rights of third parties remain in effect.
Coordinate publication so that a report does not unnecessarily expose users while the issue is being assessed or fixed. We welcome good-faith reports; these instructions do not restrict lawful reporting to a regulator or other protected disclosure.
4. Personal-data incidents
When an incident involves personal data, we assess its nature, affected information, impact and notification requirements, take appropriate containment and corrective measures, and document the response. Not every operational problem is a reportable personal-data breach.
Where notification to a supervisory authority is required under the GDPR or Serbian data-protection law, it is made without undue delay and, where feasible, within 72 hours after awareness. The relevant law determines the notification threshold and competent authority. A high risk to affected people can require a separate notice to them without undue delay. We do not wait for every investigation detail before making an initial notice where the law requires it.
5. Protecting your account and sensitive information
Protect your sign-in credentials and device, keep software updated, check the LifeOrg domain before signing in and use additional account-protection options when available. Support will not ask you to send your password or a one-time authentication code.
Before uploading a receipt, map contribution or support attachment, remove information the feature does not need. Review public-content destinations. If you suspect unauthorized account use, contact support promptly; for privacy rights or a suspected disclosure of personal information, contact privacy@lifeorg.app.