Work-A-Beez Responsible Disclosure Policy

Last updated: July 24, 2026

Effective Date: July 23, 2026

At Work-A-Beez, security is one of our highest priorities.

We value the efforts of security researchers, customers, and members of the security community who help us identify potential vulnerabilities responsibly.

This Responsible Disclosure Policy explains how to report suspected security vulnerabilities and describes our commitment to investigating and addressing legitimate reports.

Important: This policy is not a Bug Bounty Program and does not provide financial compensation unless expressly stated in writing by LBS.


Table of Contents

  1. Purpose
  2. Scope
  3. Safe Harbor
  4. What to Report
  5. What Not to Report
  6. Reporting Guidelines
  7. Our Commitment
  8. Response Timeline
  9. Coordinated Disclosure
  10. Exclusions
  11. Legal Notice
  12. Contact Information

Purpose

This policy exists to:


Scope

This policy applies to publicly accessible Work-A-Beez systems, including:

It does not apply to third-party systems, vendors, or integrations that are not owned or operated by LBS.


Safe Harbor

If you act in good faith and follow this policy, LBS will generally not pursue legal action against you for your security research.

To qualify for Safe Harbor you must:

Safe Harbor does not apply to malicious activity or violations of applicable law.


What to Report

Examples of reportable vulnerabilities include:

Authentication Issues


Authorization Issues


Injection Vulnerabilities

Examples include:


Cross-Site Vulnerabilities

Examples include:


API Vulnerabilities

Examples include:


Sensitive Data Exposure

Examples include:


Security Misconfigurations

Examples include:


Other Security Issues

Examples include:


What Not to Report

The following generally do not qualify as security vulnerabilities:

Reports lacking sufficient evidence may be closed without action.


Activities That Are Not Permitted

Researchers must not:


Testing Guidelines

When conducting research:

You should:


Reporting Guidelines

Please include as much information as possible.

Helpful information includes:

Reports containing sufficient detail can generally be investigated more quickly.


How to Report

Please send vulnerability reports to:

Security Team

Email:

info@lbsconnect.net

Subject Line:

Security Vulnerability Report

Please encrypt sensitive reports when practical.


Our Commitment

When receiving a legitimate report we will generally:

  1. Acknowledge receipt
  2. Validate the report
  3. Assign severity
  4. Investigate
  5. Develop a remediation plan
  6. Deploy a fix
  7. Notify the reporter (when appropriate)

Typical Response Timeline

Although timelines vary depending upon complexity, our general goals are:

Activity Target Time
Acknowledgement Within 3 business days
Initial Review Within 5 business days
Investigation As soon as practical
Resolution Based on severity
Public Disclosure After remediation

These timelines are goals rather than contractual commitments.


Coordinated Disclosure

We request that researchers:

Premature public disclosure may increase customer risk.


Recognition

At our discretion, we may acknowledge individuals who responsibly disclose significant vulnerabilities.

Recognition may include:

Unless otherwise stated, Work-A-Beez does not currently operate a monetary bug bounty program.


Severity Assessment

Reports are evaluated based upon:

Severity may be classified internally as:


Exclusions

This policy does not authorize:


Legal Notice

Nothing in this policy:

LBS reserves all legal rights regarding unauthorized access or unlawful conduct.


Contact Information

Security Team

Work-A-Beez by LBS

Website

https://www.workabeez.net

Email

info@lbsconnect.net

General Support

info@lbsconnect.net


Related Documentation


Revision History

Version Date Description
1.0 July 23, 2026 Initial publication

Disclaimer

This Responsible Disclosure Policy is intended to facilitate the responsible reporting of security vulnerabilities affecting Work-A-Beez. It does not constitute authorization to access systems without permission or engage in activities prohibited by law. LBS reserves the right to modify or discontinue this policy at any time without prior notice.


© 2026 LBS. All rights reserved.

Work-A-Beez® is a product and trademark of LBS. All rights reserved.