Security

If you have found a security issue in a Kelso program or on this website, we want to hear about it. This page says what is in scope, how to reach us, and what you can expect.

Scope

How to report

Write to security@kelso.computer. Include the program or URL, the steps to reproduce, and what you observed. English is preferred. Please leave other people's data out of the report.

If you are not sure something is in scope, write first and wait—do not test. If the evidence is sensitive, say so in the first message and wait for a private channel before you send it.

What to expect

Safe harbor

Research done in good faith and within this policy is authorized, and we will not take legal action over it, including accidental and/or good-faith mistakes.

We treat this work as authorized access under applicable anti-hacking laws. We will not bring an anti-circumvention claim for steps that were necessary to demonstrate the issue. Terms of service or acceptable-use rules that would otherwise forbid this testing do not apply to work done under this policy.

Good faith means: no access to data beyond what proves the issue, no destruction of data, no disruption of service, and ninety days for us to fix the issue before you publish, or longer if we ask and you agree. If a third party starts legal action and you stayed inside this policy, we will say so.

Out of scope


This policy is also announced in security.txt.