Security
If you have found a security issue in a Kelso program or on this website, we want to hear about it. This page says what is in scope, how to reach us, and what you can expect.
Scope
- kelso.computer and its subdomains.
- Programs published by Kelso, on every platform.
How to report
Write to security@kelso.computer. Include the program or URL, the steps to reproduce, and what you observed. English is preferred. Please leave other people's data out of the report.
If you are not sure something is in scope, write first and wait—do not test. If the evidence is sensitive, say so in the first message and wait for a private channel before you send it.
What to expect
- We acknowledge every report within five business days.
- We give an initial assessment within ten business days.
- We keep you informed while we work on a fix, and we tell you when it ships.
- Give us ninety days to ship a fix before you publish. If we need more time, we will ask.
- With your permission, we credit you once the issue is resolved.
- There is no bounty program.
Safe harbor
Research done in good faith and within this policy is authorized, and we will not take legal action over it, including accidental and/or good-faith mistakes.
We treat this work as authorized access under applicable anti-hacking laws. We will not bring an anti-circumvention claim for steps that were necessary to demonstrate the issue. Terms of service or acceptable-use rules that would otherwise forbid this testing do not apply to work done under this policy.
Good faith means: no access to data beyond what proves the issue, no destruction of data, no disruption of service, and ninety days for us to fix the issue before you publish, or longer if we ask and you agree. If a third party starts legal action and you stayed inside this policy, we will say so.
Out of scope
- Denial of service, spam, or brute force against live systems.
- Social engineering or phishing of people at Kelso.
- Physical attacks on offices or hardware.
- Issues in third-party services we use, unless our configuration causes them.
- Reports from automated scanners with no demonstrated impact.
This policy is also announced in security.txt.