Security

Responsible vulnerability disclosure

We take security seriously and appreciate those who help us improve it. If you've found a vulnerability, tell us and we'll work with you.

Safe harbor

If you research and report in good faith following this policy, we will not pursue or support legal action against you, and we consider your research authorized.

How to report

Email [email protected] (or [email protected]) with: a description, reproduction steps, impact and, if you can, a proof of concept. Encrypt your email if the finding is sensitive; we'll provide a key if needed.

We aim to respond within 3 business days and will keep you posted through to resolution.

Rules

Don't access data that isn't yours, don't degrade the service (no DoS), don't social-engineer our team or users, and give us a reasonable window to fix before public disclosure.

Much of the surface is open source (github.com/kooveio) — auditing the client and the encryption primitives is welcome and needs no permission.

Scope and rewards (honest)

We do NOT currently run a paid bug bounty; it will come when the product sustains it. We'll publicly credit reporters who want it in a security hall of fame.

In scope: koove.io, the API, the SDK, the CLI and the encryption primitives. Out of scope: third-party services (Vercel, Stripe) and findings that require physical access to an already-compromised device.