Security
Responsible disclosure
We build protective software, so we take reports about our own security seriously. If you have found a vulnerability in an KCNEX product, we want to hear from you.
Report a vulnerability
security@kcnex.comInclude the product, the version, and steps to reproduce. If you need encryption, say so in your first message and we will arrange it.
What we commit to
- We will acknowledge your report within five working days.
- We will tell you honestly whether we consider it a vulnerability, and why.
- We will keep you updated while we work on a fix, and tell you when it ships.
- We will credit you publicly if you want the credit, and stay quiet about you if you do not.
- We will not pursue legal action against researchers who follow the guidelines below.
What we ask of you
- Give us a reasonable window to fix the issue before disclosing it publicly.
- Do not access, modify, or delete data belonging to anyone else. If you encounter user data, stop and tell us.
- Do not run denial-of-service tests, send spam, or use social engineering against our team or our users.
- Test only against your own accounts and installations.
Scope
Every product listed on our products page is in scope, along with this website and our product websites. Third party services we merely use — our host, our email provider — should be reported to those vendors directly.
Out of scope
Reports that amount only to scanner output with no demonstrated impact, missing security headers with no exploit path, or social engineering of our staff are generally not something we will action. If you think your case is an exception, tell us why and we will look.
No bounty, yet
We are a small company and we do not currently run a paid bounty programme. We would rather say that up front than imply a reward that does not exist. Credit, a genuine thank you, and a fast fix are what we can offer today.