Responsible Security Disclosure Policy

KairosVector’s policy for security researchers and external parties who responsibly report potential vulnerabilities and security concerns.

Last Updated: August 13, 2026

1. Introduction

KairosVector is committed to maintaining secure and trustworthy services. We recognize the important role security researchers, customers, partners, and external contributors play in identifying potential security weaknesses.

This Responsible Security Disclosure Policy provides guidelines for reporting suspected vulnerabilities so they can be reviewed, investigated, and addressed responsibly.

2. Scope

This policy applies to security vulnerabilities discovered in KairosVector websites, publicly available services, and systems operated directly by KairosVector.

Reports involving third-party products, external platforms, or customer environments should be directed to the appropriate responsible organization.

3. How to Report a Vulnerability

Security researchers should report suspected vulnerabilities through the official KairosVector security contact channel. Reports should include enough information to allow investigation and verification.

4. Required Information

  • Description of the potential vulnerability.
  • Affected service, page, or component.
  • Steps required to reproduce the issue.
  • Potential security impact.
  • Supporting evidence where appropriate.

5. Disclosure Process

KairosVector will review submitted reports, validate the reported issue where possible, communicate with the reporter when additional information is required, and work toward appropriate remediation.

Security issues are evaluated based on severity, impact, affected systems, and practical remediation requirements.

6. Researcher Guidelines

  • Do not access, modify, delete, or expose data belonging to others.
  • Do not perform actions that may disrupt service availability.
  • Do not conduct social engineering attacks against employees or customers.
  • Provide reasonable time for investigation before public disclosure.
  • Only test systems you are authorized to evaluate.

7. Limitations

This policy does not authorize security testing against systems outside KairosVector ownership or control. Unauthorized access, disruption, data extraction, or malicious activity may violate applicable laws.

8. Contact

For responsible security disclosures, contact KairosVector through the official security contact channel published on the website.

Scroll to Top