This page is intended to explain our practices clearly. It does not replace any signed client agreement, order form, or statement of work.
Our approach
Lightib LLC, doing business as AutomatorX.ai, designs security controls according to the nature of each website, system, integration, and client engagement. Measures may include access controls, least-privilege permissions, encryption in transit, environment separation, logging, backups, dependency maintenance, and vendor review.
Security practices evolve with the services and risks involved. This page describes our general approach and is not a certification, audit report, warranty, or promise that any system is immune from attack.
Client projects
Security scope, hosting responsibilities, data flows, retention, support, incident handling, and any compliance requirements for a client project should be documented in the applicable agreement and technical design.
Clients are responsible for protecting credentials under their control, managing authorized users, reviewing access, following deployment guidance, and notifying us promptly about suspected compromise affecting our work.
Report a vulnerability
If you believe you found a security vulnerability in an AutomatorX.ai-owned website or system, email [email protected] with a clear description, affected URL or component, reproduction steps, and the potential impact. Do not include personal information or credentials that are not necessary for the report.
Good-faith research
- Test only systems owned by Lightib LLC unless you have separate written permission.
- Avoid accessing, changing, downloading, retaining, or deleting other people’s data.
- Do not use denial-of-service, social engineering, phishing, malware, physical attacks, or automated testing that degrades service.
- Stop testing and report promptly if you encounter sensitive information or gain unintended access.
- Give us a reasonable opportunity to investigate and remediate before public disclosure.
Our response
We aim to acknowledge useful reports, investigate them, and communicate material progress when practical. We do not operate a paid bug-bounty program unless a written program says otherwise.
When research follows this policy and applicable law, we will not pursue legal action solely because of that good-faith research. We cannot authorize activity on third-party infrastructure.
