Security
Vulnerability Disclosure Policy
Last updated: September 2026
We build software that other organizations use to run their own security. That raises the bar for ours. However much care goes into a system, vulnerabilities happen — and we would rather hear about one from you than discover it in an incident.
How to report
Send your findings by e-mail to contact@kaitosec.app. Please include enough detail for us to reproduce the issue: the affected URL or component, the steps you took, and what you observed. A proof of concept, a request log or a short screen recording shortens our response time considerably.
A machine-readable version of this contact is published at https://kaitosec.app/.well-known/security.txt, following RFC 9116.
Scope
This policy covers the services KaitoSec operates itself: the website kaitosec.app, the KaitoSec platform, and the APIs behind them.
Systems that third parties operate on our behalf are out of scope — report those to the provider in question. If you are unsure whether something belongs to us, ask before you test.
Out of scope
The findings below are known to us, accepted, or carry no impact on their own. We close such reports without a further assessment:
- Clickjacking on pages that carry no sensitive action.
- CSRF on login, logout, or other unauthenticated forms.
- Attacks that require a man-in-the-middle position or physical access to a device.
- Attacks that require social engineering of our staff or our customers.
- Anything that degrades availability for others — denial of service, load and stress testing.
- Content spoofing and text injection without a demonstrated attack vector.
- E-mail spoofing, and SPF, DKIM or DMARC records on domains we do not send from.
- Missing DNSSEC, CAA or security response headers without a demonstrated impact.
- Missing Secure or HttpOnly flags on cookies that carry no session or authentication state.
- Dead links, outdated library versions without a working exploit, and account enumeration.
Rules for testing
- Do not point automated scanners at tenants or data belonging to other KaitoSec customers, and do not test in a way that degrades the service for anyone else.
- Behind a login, use your own account and your own test data. If you need a test environment for an on-premise installation, please get in touch with us.
- Do not take a finding further than the proof requires: read no more data than necessary, and never delete, alter or take out data belonging to other people.
- If you reach personal data by accident, stop, tell us straight away, and delete your copy.
Disclosure
- Give us the chance to fix the issue and inform affected customers before you tell anyone else.
- If you want to publish your research — a talk, a blog post, an advisory — send us a draft at least 30 days before the publication date so we can check it for customer data.
- Do not publish data from customer tenants, customer documents, or information about our employees, contractors or partners.
What we commit to
- We confirm receipt of your report within three business days.
- Within five business days you get our assessment and, where we can give one, an expected date for the fix.
- We keep you posted while we work on it, and we tell you when it is fixed.
- We treat your report confidentially and do not pass your personal details to third parties without your permission, unless we are legally required to disclose them.
- When we publish something about a resolved issue, we credit you as the finder — unless you would rather stay anonymous.
No bug bounty
We do not run a paid bug bounty program and we do not pay for reports. What we offer is a fast, honest process and public credit. We would rather say so here than have you spend days on research expecting a payout.