Responsible Disclosure
We take security seriously. If you discover a vulnerability in Kraal Code, we want to hear from you.
How to report
If you believe you have found a security vulnerability in Kraal Code or our website, please report it to:
Email: security@kraalcode.com
Please include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any supporting evidence (screenshots, logs)
What to expect
- Acknowledgement: within 3 business days
- Initial assessment: within 10 business days
- Resolution timeline: communicated after assessment
Safe harbour
We support responsible disclosure. If you:
- Make a good-faith effort to avoid privacy violations, data destruction, and service disruption
- Only interact with your own accounts or test accounts
- Do not exploit a vulnerability beyond what is necessary to demonstrate it
- Provide us reasonable time to resolve the issue before public disclosure
Then we will not pursue legal action against you for your research.
Scope
In scope:
- kraalcode.com and its subdomains
- The Kraal Code ERP application
- API endpoints
Out of scope:
- Social engineering attacks
- Denial of service attacks
- Third-party services we use