Land Air & Sea Logistics Int LLC moves freight for shippers who trust us with commercially sensitive information. We take reports of security weaknesses seriously and we will not take legal action against researchers who follow this policy.
Report a vulnerability
Email security@landairseaint.com. Include the affected URL or endpoint, the steps to reproduce, and what an attacker could achieve. We acknowledge within 3 business days and aim to give a remediation status within 30 days. We accept reports in English and Spanish.
Machine-readable contact details are published at /.well-known/security.txt.
In scope
- landairseaint.com and its subdomains
- LASLINT Operations Hub, our freight-operations platform
- Public APIs and forms operated by LASLINT
Out of scope
- Denial-of-service, volumetric, or load testing of any kind
- Social engineering, phishing, or physical attacks against our staff or offices
- Reports produced solely by an automated scanner with no demonstrated impact
- Missing best-practice headers or TLS configuration with no exploitable consequence
- Third-party services we do not operate — report those to their owner
Safe harbor
If you make a good-faith effort to comply with this policy, we will treat your research as authorized, will not pursue civil or criminal action, and will work with you to resolve the issue quickly. In return: access only the minimum data needed to prove the finding, never modify or destroy data, never access another person’s account or freight records, delete any retrieved data once you have reported it, and give us reasonable time to fix the issue before disclosing publicly.
We do not currently run a paid bug-bounty program. We do credit researchers who ask to be credited.
How we protect data
HTTPS is enforced site-wide with HSTS, and a Content-Security-Policy restricts which scripts may execute. Application data is encrypted in transit and at rest. Access to operational systems is role-based and least-privilege. Where we integrate a third-party system on your behalf, we use OAuth rather than asking for your password; the resulting access tokens are held server-side, encrypted, never exposed to a browser, and revoked and deleted when you disconnect the integration. What we collect and how long we keep it is described in our Privacy Policy.
Contact
Security reports: security@landairseaint.com. Everything else: management@landairseaint.com. Postal: Land Air & Sea Logistics Int LLC, 2807 N Parham Rd, Ste 320 #2639, Henrico, VA 23294.
