Security
LAST UPDATED 19 AUGUST 2026
Found something in one of these sites? Write to addie@lamarrlabs.com. You will get a human acknowledgment within 5 business days, and good-faith research is protected under the safe harbor below.
Why this page exists
A firm that advises other organizations on cryptographic risk should be reachable when someone finds a problem with its own systems. This policy follows RFC 9116, and the machine-readable version lives at /.well-known/security.txt.
In scope
lamarrlabs.comand everything served from it, including the briefing and speaking formsfieldguide.lamarrlabs.com, the Post-Quantum Field Guidelamarrlabs.com/resources, the plain-English resources hub
Out of scope
These are either outside LaMarr Labs control or not the kind of finding this policy is for.
- Denial of service, volumetric testing, or anything that degrades availability for other readers
- Social engineering of LaMarr Labs, its contractors, or its service providers, and any physical attack
- Findings in third-party services the sites depend on. Report those to the provider, and tell us so we can act on our side.
- Missing hardening headers or configuration weaknesses with no demonstrated impact, and automated scanner output submitted without a working demonstration
- Factual errors in published material. Those are genuinely wanted, and they go to the same address, but they are corrections rather than vulnerabilities.
How to report
Email addie@lamarrlabs.com with as much of the following as you have. A short report with a working reproduction is worth more than a long one without.
- The affected site, URL, and the type of issue
- Steps to reproduce it, and what an attacker could actually do
- Any proof of concept, screenshots, or request captures
- How you would like to be credited, if you would
If you need to send something sensitive and want an encrypted channel, say so in a first message and one will be arranged.
What you can expect
- An acknowledgment within 5 business days, written by a person rather than generated
- An assessment and a plan within 10 business days of that
- Progress updates until the issue is resolved, and confirmation when it is
- Public credit if you want it, and none if you would rather stay anonymous
There is no bug bounty and no payment. The firm is small and says so plainly rather than implying a reward that does not exist.
Safe harbor
If you make a good-faith effort to follow this policy during your research, LaMarr Labs will treat your research as authorized, will not pursue or support legal action against you in connection with it, and will say so if a third party raises the question.
Good faith means, concretely:
- You stay within the sites listed as in scope, and stop as soon as you have confirmed a finding
- You do not access, modify, delete, or keep data that is not yours, and you tell us straight away if you encounter any
- You do not degrade the sites for other readers, and you do not attempt extortion
- You give a reasonable opportunity to fix the issue before disclosing it publicly, and 90 days is treated as reasonable unless we agree otherwise
This safe harbor covers what LaMarr Labs Inc. controls. It cannot waive the rights of a third party or override the law.