Report a vulnerability
Email admin@lanzalabs.io with a concise description and safe reproduction steps. Do not send exploit payloads, credentials, customer data, active scanning results, or destructive proof-of-concept content.
Scope and handling
- Only
cascadeatlas.comand its HTTPSwwwredirect are intended public surfaces. - Do not perform denial-of-service, persistence, social engineering, credential attacks, automated broad scanning, or tests affecting third parties.
- Provider citations are navigational references, never authorization to execute or retrieve linked exploit content.
- Public errors and receipts must not expose secrets, internal paths, private addresses, SQL, or stack traces.
Architecture minimum
PostgreSQL and worker services are private; the web role is read-only; query and graph resources are capped; containers have no Docker socket; releases are allowlisted, scanned, checksummed, immutable, and reversible.