Security
Responsible disclosure policy
If you believe you have found a security vulnerability in lombardprivate.com, we want to hear from you. This policy explains how to report it privately, what is in scope, and the commitments we make to researchers who act in good faith.
Last updated 9 October 2026
Our commitment
We take the security of our clients’ accounts and collateral seriously, and we value the work of independent researchers. If you report a vulnerability in line with this policy, we will work with you to understand and resolve it, and we will not pursue you for your research.
How to report
Reports are received through the secure messaging of the client area, the only channel we use with anyone. Opening a client area is free and anonymous, and takes about a minute: you do not need to give a name, an email address or a phone number. Once signed in, send a message and choose the Security topic.
One channel, for your protection too
We do not accept reports by email, social networks or messaging apps, and we will never contact you through them. If someone claiming to be from Lombard Private contacts you about a report outside your client area, it is not us.
What to include
- A description of the vulnerability and of its potential impact.
- The affected page, address or feature.
- Step-by-step instructions to reproduce it, with any proof-of-concept code.
- Screenshots or a short recording, if they help.
- The browser, system and tools you used.
- Whether you would like to be credited, and under which name or handle.
Please write in English if you can, and send one report per vulnerability.
Scope
This policy covers lombardprivate.com, including the client area and the public endpoints it serves. We are particularly interested in:
- Account takeover, and flaws in authentication, passkeys, one-time codes, recovery or sessions.
- Cross-site scripting, injection, request forgery and other flaws that let an attacker act on a client’s behalf.
- Unauthorised access to client data, statements or messages.
- Business-logic flaws affecting deposit or return addresses, payout details, balances, loan-to-value, margin calls or liquidations.
- Weaknesses in our security headers or encryption settings, where you can show a real, exploitable impact.
Out of scope
- Denial-of-service, load or volumetric testing.
- Social engineering, phishing or physical attacks against our staff or clients.
- Reports from automated scanners, missing best-practice headers or DNS records, without a demonstrated impact.
- Clickjacking on pages with no sensitive action, self-XSS, or issues that require physical access to an unlocked device.
- Content or text injection without a security impact, and rate limits on non-sensitive pages.
- Vulnerabilities in outdated browsers, or in third-party services, public blockchains, block explorers or wallets that we do not operate: please report those to their owners.
Rules of engagement
- Only test against client areas that you created yourself.
- Never access, modify or delete data that is not yours. Stop as soon as you have shown the issue.
- Do not attempt to move, withdraw or liquidate collateral, or to trigger, redirect or alter a payout.
- Do not degrade the service for others: no denial-of-service and no high-volume automated scanning.
- Do not use the vulnerability beyond what is needed to demonstrate it.
- Keep the details confidential until the issue is fixed and we have agreed a disclosure date with you.
- Comply with the laws that apply to you.
Safe harbour
If you make a good-faith effort to comply with this policy:
- we will consider your research authorised;
- we will not take legal action against you, and will not ask anyone else to, in relation to that research;
- if a third party takes legal action against you for research carried out under this policy, we will make it known that your actions were authorised by us.
This safe harbour applies to our own systems only. We cannot authorise testing of systems that belong to others, including the payment systems, blockchains and services we rely on.
What happens next
We acknowledge your report in your client area, keep you informed while we investigate and fix the issue, and tell you when it has been resolved. We may ask you for more detail or for help in confirming the fix. Once the fix is in place, we agree with you on whether and when the issue can be disclosed publicly.
Recognition and rewards
With your permission, we credit researchers who report valid vulnerabilities, once the issue is fixed. Any financial reward is at our discretion and depends on the severity of the issue and the quality of the report; there is no fixed reward table, and a reward is never a condition for reporting.
security.txt
Our contact details for security researchers are also published in machine-readable form, following RFC 9116, at lombardprivate.com/.well-known/security.txt.