Lushu Limited
Paid security research program

Help us harden the path between sites.

Lushu Limited rewards original, responsibly disclosed vulnerabilities that demonstrate meaningful security impact in our SD-WAN platform, managed edge, and supporting network services.

Program scope

Three areas of focus

Valid reports in every area are eligible for payment after technical validation.

Track 01Paid

Control Plane & Policy

Protect the systems that authenticate operators and turn intent into network policy.

  • Authentication or authorization bypass
  • Cross-tenant administrative access
  • Unauthorized policy, route, or configuration changes
Track 02Paid

Transport & Segmentation

Preserve traffic confidentiality and isolation across sites, tenants, and overlays.

  • Cross-tenant traffic or route leakage
  • Tunnel or key-isolation failures
  • Unauthorized traffic interception or redirection
Track 03Paid

Edge & Supply Chain

Secure managed edge nodes and the software path used to operate them at scale.

  • Remote code execution on a managed edge
  • Update or command-channel integrity bypass
  • Device secret extraction or fleet-wide compromise

Rewards

Impact determines the reward.

We assess each verified report by severity, exploitability, affected scope, and report quality. Higher rewards are reserved for findings that cross trust boundaries, expose customer traffic, or enable control of multiple sites. Duplicate or previously known issues are not eligible.

Payment commitment

Every original report with validated security impact receives a monetary reward agreed after triage.

A useful report includes

  • 01A clear impact statement and affected component
  • 02Reproducible steps with a minimal proof of concept
  • 03Relevant request, response, packet, or log evidence
  • 04Any conditions required to reproduce the issue safely

Research rules

Keep testing controlled.

Test only systems and accounts you own or have explicit permission to use. Stop after proving impact. Do not retain customer data, degrade availability, perform denial-of-service testing, use social engineering, or access another customer's environment beyond the minimum evidence required.

Not eligible

Reports need real impact.

Automated scanner output without validation, rate-limit observations without a security consequence, missing headers, self-XSS, third-party services outside Lushu's control, and findings that require physical access without crossing a defined trust boundary are out of scope.

Responsible disclosure

Found something that matters?

Send the report before public disclosure. We will acknowledge it, validate the impact, and coordinate remediation with you.

Report securely