Responsible disclosure
Report a vulnerability and we will work with you in good faith.
Scope
Nokkam, kriyaetive.com, and our public infrastructure. Please do not test against a client workspace you do not own, and do not access, modify or exfiltrate data that is not yours.
How to report
Email security@kriyaetive.com with steps to reproduce and any proof of concept. Encrypt if you prefer, ask us for a key.
What we promise
- We aim to acknowledge within 3 working days.
- An assessment and an intended fix window within 10 working days.
- Credit in our notes if you want it, and no legal action for good faith research within this scope.
Out of scope
Volumetric denial of service, social engineering of our team or clients, physical access, and findings from automated scanners without a demonstrated impact.