Security is fundamental to LexAI. If you've discovered a vulnerability, we appreciate your help in keeping our platform secure.
Effective: May 5, 2026

Security of the LexAI platform is fundamental to us. LexAI is built on a zero-knowledge architecture, and user trust in the protection of their data is central to our product. If you have discovered a security vulnerability in our platform, we appreciate you reporting it in accordance with this policy.
Important notice: LexAI does not currently operate a public bug bounty program and does not offer monetary rewards for reported vulnerabilities. Active security testing (penetration testing, fuzzing, scanning, etc.) without our prior written consent is not permitted — see Section 6.2(b) of our Terms of Use. This policy applies in cases where you discover a vulnerability through normal use of the platform or through independent security research that does not violate our Terms of Use.
We accept reports under this policy for:
We do not accept reports for:
If you report a vulnerability to us, we ask that you:
If you proceed in accordance with this policy:
Submit reports to support@lexaitechnologies.com with the subject line beginning [SECURITY] so that we can quickly identify and escalate the report. Reports should include:
For sensitive reports (in particular vulnerabilities in the authentication or cryptographic layer), we recommend encrypting communications. A PGP key for encrypted communication is available on request — include this request in your initial email and we will return the public key to you.
We use the CVSS v3.1 standard to assess severity. Remediation priority is determined primarily by:
Vulnerabilities that could lead to a compromise of the zero-knowledge architecture (i.e. obtaining unencrypted access to user conversations or documents) are treated as the highest priority.
This policy:
LexAI reserves the right to update this policy at any time. The current version is always available at https://www.lexaitechnologies.com/vulnerability-disclosure. Changes do not have retroactive effect on reports submitted prior to the effective date of the new version.
LexAI Technologies, s.r.o.
Školská 660/3, Praha 1 — Nové Město, 110 00 Praha 1
Email: support@lexaitechnologies.com
Web: www.lexaitechnologies.com
Version 1.0 — effective from 5 May 2026