Responsible Disclosure Policy

Lineage

Last updated: August 11, 2026

Our Commitment to Security

At Lineage, safeguarding the security and privacy of our customers, partners, and systems is a responsibility we take seriously. We recognize that no organization is immune to technical security vulnerabilities, and we deeply value the security research community’s role in helping us identify and address potential issues.

If you believe you have discovered a security vulnerability affecting any of our systems, websites, or services (collectively, the “Lineage IT Environment”), we encourage you to share it with us. Working together, we can keep our environment safe for everyone who relies on us.

Scope

This Responsible Disclosure Policy (“Policy”) applies to security vulnerabilities discovered in the Lineage IT Environment, including our website at www.onelineage.com (the “Lineage Website”). Note: anyone who accesses or uses the Lineage Website must, at any and all times, comply with our Lineage Website Terms and Conditions of Use.

How to Report a Vulnerability

Please send details of any suspected security vulnerability to our Cyber Incident Response Team (CIRT):

To help us review and respond effectively, please include as much of the following as you can provide:

  • A clear description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • The affected URLs, systems, or components
  • Any supporting materials, such as screenshots, logs, or a proof-of-concept

If your report involves sensitive information, please handle it responsibly and share only what is necessary to demonstrate the issue.

What You Can Expect From Us

When you submit a report, we will:

  • Acknowledge receipt of your submission
  • Review the reported issue and assess its validity and severity
  • Take appropriate remediation action where needed
  • Keep you informed of our progress where it is practical to do so

Some issues take time to investigate and resolve thoroughly, so we appreciate your patience throughout the process.

Guidelines for Responsible Disclosure

To protect our users and support a constructive process, we ask you:

  • Allow us a reasonable opportunity to investigate and address the issue before disclosing any details publicly
  • Avoid accessing, modifying, or deleting data that does not belong to you
  • Avoid any actions that could disrupt or degrade the availability of our services, such as denial-of-service testing
  • Limit your testing to what is necessary to demonstrate the vulnerability
  • Comply with all applicable laws and regulations
  • Never test any system other than the Lineage IT Environment set forth in the “Scope” section of this Policy above
  • Never disclose vulnerability information, except as set forth in the “How to Report a Vulnerability” section of this Policy
  • Never engage in physical testing of facilities or resources, execute or attempt to execute “Denial of Service” or “Resource Exhaustion” attacks, or introduce malicious software into the Lineage IT Environment
  • Never engage in social engineering or send unsolicited electronic mail to Lineage users, including “phishing” messages
  • Never test third-party applications, websites, or services that integrate with or link to or from the Lineage IT Environment
  • Never delete, alter, share, retain, or destroy Lineage data, or render Lineage data inaccessible, or use an exploit to exfiltrate data
  • Never establish command line access, establish a persistent presence on or in the Lineage IT Environment, or “pivot” to other portions of the Lineage IT Environment outside the scope of this Policy.
  • Cease testing and notify Lineage immediately upon discovery of a vulnerability, or if an exposure of nonpublic data, and, purge any stored Lineage nonpublic data upon reporting a vulnerability.

Recognition

LINEAGE DOES NOT OPERATE A PAID BUG BOUNTY PROGRAM, AND WE DO NOT OFFER FINANCIAL COMPENSATION OR EXTERNAL PAYMENTS TO SECURITY RESEARCHERS OR OTHER INDIVIDUALS.

That said, we sincerely appreciate the time, effort, and integrity of those who choose to help us strengthen our security. Your support in responsibly disclosing potential issues makes a genuine difference, and we are grateful for it.

Legal Disclaimer

Your participation in furnishing Lineage information on a vulnerability is voluntary and does not create any expectation of employment, contractor relationship, or service-related compensation by Lineage. Information voluntarily submitted to Lineage will be considered non-confidential and non-proprietary. By submitting information, you agree that Lineage may use the information, in whole or in part, without restriction. Submission of information does not grant you any rights or entitlement and does not create any obligation on the part of Lineage.

Thank You

We are committed to engaging with the security community in a spirit of collaboration and mutual respect. Thank you for helping us keep Lineage secure.