Loading LawSensai…
This page is the reporting surface for security researchers reviewing the Criminal Defense Command Center. It explains what is in scope, the safe-harbor terms we commit to, and how we respond once you send us a finding. The platform-wide security posture lives at /trust/brain.
Last updated: June 9, 2026.
The Criminal Defense Command Center serves people facing criminal charges, often during the most consequential period of their lives. A bug on our marketing landing is a bug. A bug that leaks matter data, bypasses authentication on a CDC route, or weakens the audit log can put a real person at risk of an outcome they cannot undo.
We will triage any disclosure within 72 hours. Findings that could undermine attorney-client privilege under the Kovel agency framework, or that could deanonymize an aggregate stat on the public Trust Center, are treated as critical and get same-day attention. We publish acknowledgments (with permission) and do not send legal threats to researchers acting in good faith.
These are the primitives that, if broken, would cause the most harm. Please read this list before you start.
We are most interested in findings that fall into one of these buckets:
/dashboard/criminal-defense/* consumer routes (dashboard, triage, intake, record clearing, bail, court dates, packet review)/api/cd/* consumer APIs (matters, triage, intake, eligibility screener, packet generation, attorney match)/attorney/dashboard/leads/criminal-defense/* attorney lead portal/admin/cd/* admin surfaces (unauthenticated probes only; do not access real admin data)/trust/criminal-defense and its stats APInode_modules or a third-party dependency we do not vendor/criminal-defense and the per-state SEO pages at /criminal-defense/[state]. These read static or DB-backed content and do not perform writes; report a finding only if you can demonstrate an impact on the consumer dashboard or an APIWe will not pursue legal action against researchers who:
Email security@lawsens.ai with:
PGP key for sensitive reports is available on request. Tag privilege-relevant or survivor-safety-relevant findings with [PRIVILEGE] or [SAFETY] in the subject for same-day triage.
[PRIVILEGE] or [SAFETY])These are the same disclaimers we surface at point of capture inside the product. They are included here so any researcher reviewing user-facing copy can verify that the disclosures match the canonical source.
Triage surface: LawSensai provides legal information, document organization, and attorney matching. It is not a law firm. It does not replace advice from a criminal defense attorney.
Case Intelligence report: This report is an organizational summary. It is not legal advice, an opinion on the merits, or a prediction of outcome.
Pre-engagement privacy: This information is not protected by attorney-client privilege. Government investigators may be able to compel disclosure.
The Criminal Defense Command Center is scoped for an annual external penetration test by an independent third party. The test report's executive summary is published to this page once available; the detailed findings stay internal until remediated and re-tested.
When a researcher disclosure leads to a code change, we link the commit + PR here with the researcher's permission. The list below is intentionally short because the platform is young; we expect it to grow.
No public disclosures yet. Internal audit findings and their fixes are tracked in the repository underCriminalDefenseCommandCenter_QA_Audit.md and the V2.9 remediation sprint notes.
We also publish aggregate statistics for: