Report a vulnerability.
If you find a security problem in One or on lughlabs.ai, email security@lughlabs.ai.
What to include
What you found, where (the URL, or the app and its version), the steps to reproduce it, and what an attacker could do with it. Send only the data needed to show the problem.
Scope
In scope: lughlabs.ai and the subdomains we run, the One apps, and the hosted service.
Out of scope: denial of service, spam, social engineering, physical attacks, scanner output without a demonstrated impact, and services run by other companies, such as our email and payment providers.
Safe harbour
If you act in good faith and follow this page, we won’t take legal action against you for your research. Test only with your own accounts and data. If you reach someone else’s information, stop, tell us, and don’t keep or share it. Don’t degrade the service, and give us reasonable time to fix the problem before you disclose it.
What happens next
We acknowledge reports within 2 business days, keep you updated, and aim to fix critical issues within 7 days. We don’t offer payment for reports.

