← All legal documents

Security Policy

LighChat Security Policy and Vulnerability Disclosure

Last updated: 2026-08-03 Version: 1 Contact: security@lighchat.online

1. Scope

This policy covers the LighChat service and applications operated by KDS Consulting Inc:

  • lighchat.online and its subdomains (web/PWA, API, Cloud Functions);
  • the LighChat mobile applications (iOS, Android) and desktop applications;
  • our Firebase project resources (Firestore, Storage and Realtime Database rules, callable functions);
  • our media and TURN infrastructure for calls.

Out of scope: third-party services we rely on (report those to their own vendors), social-engineering of our staff or users, physical attacks, denial-of-service testing, spam or content-injection reports with no security impact, and findings that require a rooted/jailbroken device plus physical access.

2. How we protect your data

  • TLS 1.2+ for all network traffic; encryption at rest at the infrastructure provider;
  • optional end-to-end encryption for chats and calls, with private keys stored only on user devices;
  • authentication delegated to Firebase Authentication — we never see or store passwords in readable form;
  • server-side authorisation in Firestore/Storage security rules and Cloud Functions, tested by an automated rules test-suite in CI;
  • App Check attestation against automated abuse;
  • least-privilege access to production, audit logging of administrative operations;
  • periodic internal security reviews and dependency scanning.

3. Reporting a vulnerability

Email security@lighchat.online with: a description of the issue, the affected component and version, reproduction steps or a proof of concept, and the impact you believe it has. Please encrypt sensitive details if you can, and let us know how you would like to be credited.

Our commitments:

StepTimeline
Acknowledge your report3 business days
Initial assessment and severity rating10 business days
Fix for critical issuesTarget 30 days
Fix for other issuesTarget 90 days
Public credit (with your consent)On release of the fix

4. Safe harbour

If you make a good-faith effort to comply with this policy, we will consider your research authorised, will not pursue or support legal action against you (including under the Computer Fraud and Abuse Act or the DMCA anti-circumvention provisions), and will work with you if a third party takes action.

To stay within the safe harbour: only test against accounts you own or have explicit permission to use; do not access, modify, exfiltrate or destroy other people's data; do not degrade the service; stop as soon as you have proof of the vulnerability; and give us reasonable time to fix it before any public disclosure (we ask for 90 days or until a fix ships, whichever is sooner).

5. Rewards

We do not currently operate a paid bug bounty. We offer public acknowledgement in our security hall of fame and will consider discretionary rewards for high-impact findings.

6. Security incidents

If we become aware of a personal-data breach, we notify supervisory authorities within 72 hours (GDPR Art. 33), affected users without undue delay, and business customers within 24 hours under the Data Processing Agreement. See the Privacy Policy for details.

7. Machine-readable contact

Our disclosure contact is published at https://lighchat.online/.well-known/security.txt in accordance with RFC 9116.