Vulnerability disclosure policy
LHV Pank AS works with the broader cybersecurity community to improve the security of its digital services. We welcome reports of vulnerabilities from ethical security researchers.
How to report
Send your report to security@lhv.ee. Please include the affected service and/or URL, clear steps to reproduce the vulnerability, a description of its impact, any prerequisites for reproduction and supporting evidence such as screenshots or a short PoC. Do not include customer data, sensitive authentication data or payment card data in your report.
PGP encryption
If your report contains sensitive technical information, you may encrypt it before sending it to security@lhv.ee using LHV Pank’s PGP public key. LHV Pank’s current public key:
Scope of authorized testing
You are authorized to perform limited good-faith security testing of LHV Pank’s publicly accessible services only if you comply with the rules below and act in accordance with applicable law. Testing must not disrupt the operation of LHV Pank’s services and must be limited to what is necessary to validate the vulnerability. If you discover that you have gained access to data you should not have access to, or have affected the operation of an LHV Pank service, you must stop your activity immediately and report the details without delay to security@lhv.ee.
Prohibited activities
Without LHV’s prior written permission, you must not:
- perform denial-of-service (DoS) testing, load testing or automated scanning that places significant load on a service or affects its availability;
- attempt to gain access to other users’ accounts or data, or use, copy, modify, delete or exfiltrate them;
- use social engineering, phishing, physical security testing, threats or extortion;
- install malware, establish persistence or attempt to conceal your activity.
Coordinated disclosure and confidentiality
All vulnerability-related information must be kept confidential. Without LHV’s prior written consent, you must not publish, share or discuss your findings with third parties, including the media or on social media. LHV will acknowledge receipt of your report and, where appropriate, work with you on coordinated disclosure. For the avoidance of doubt, if you do not receive a response from LHV, this does not give you the right to publish, share or otherwise disclose details of the vulnerability, details of how it may be exploited or any other information relating to LHV’s systems.
Acknowledgement and recognition
LHV does not currently operate a public bug bounty program. Depending on the impact and quality of your report, LHV may, at its discretion, acknowledge your contribution. Any acknowledgement, including a financial reward, is not guaranteed.
Non-compliance with this policy
If you do not comply with this policy, the authorization granted under it to test LHV’s systems does not apply to you. LHV may take protective measures, including blocking traffic or user accounts, and may pursue all available legal remedies, including reporting suspected unlawful activity to the competent authorities and seeking compensation for damages. Breach of this policy and unauthorized security testing of LHV’s systems may constitute an offence under applicable law.