Layout Documentation

Reporting an issue

If you have found something that affects the safety of somebody's money, their card, or their data, we want it now rather than politely later.

Where to send it

contact@layout.link, with "security" in the subject line so it is routed ahead of the rest of the mail. Everything else goes to the same address without it, including a bug that is only embarrassing.

If it is urgent and you would rather talk, +1 (877) 318-8673.

What to include

  • What you did, in enough detail that we can do it too.
  • What happened, and what you expected.
  • The surface: an assistant and its name, the API, one of our web pages, or the iOS app.
  • Roughly when, so we can find the trace. A restaurant name and a time is usually enough for us to pull the full record of one order.

You do not need a proof of concept exploit, and you should not build one that spends somebody else's money or touches an account that is not yours.

What we will do

We read it, we reproduce it, and we tell you what we found. If it is real and it touches money or card data, it goes to the front of the queue ahead of whatever we were doing, because that is the whole premise of this product.

We will tell you when it is fixed. If we decide not to fix something, you will get the reason rather than silence.

What we ask of you

  • Do not use somebody else's account, order, or card.
  • Do not place real orders at real restaurants to demonstrate something. Real food gets made.
  • Do not run load or denial of service tests against us.
  • Give us a reasonable window to fix an issue before publishing it.

What we will not do

Argue with you about severity in order to avoid fixing something. If it is real, it is real, and a finding that makes us look bad is still worth more to us than a user finding it in the middle of an order.

Updated August 17, 2026