Vulnerability Disclosure Policy
Last updated: August 2, 2026
We welcome reports from security researchers and are committed to working with the community to verify and address vulnerabilities. This policy sets out how to report and what to expect.
Scope
The kybercrypt.com service, its APIs, and our official client applications. Third-party services we rely on (see Subprocessors) are out of scope and should be reported to their respective programs.
How to report
Email security@kybercrypt.com with a description, reproduction steps, and impact. See also /.well-known/security.txt.
Safe harbor
We will not pursue legal action against researchers who, in good faith, comply with this policy: who test only against their own accounts, avoid privacy violations and data destruction, do not degrade the Service, and give us a reasonable opportunity to remediate before public disclosure.
Rules of engagement
- Do not access, modify, or delete data that is not yours; use test accounts you control.
- No denial-of-service, spam, social engineering, or physical attacks.
- Report promptly and keep details confidential until we confirm a fix.
Our commitment
We aim to acknowledge reports within a few business days, keep you updated on remediation, and credit reporters who wish to be acknowledged.