Vulnerability disclosure policy
We take the security of Keel and our customers' data seriously. If you believe you have found a security vulnerability, we want to hear from you, and we will work with you to understand and resolve it quickly.
How to report
Email [email protected] with:
- A clear description of the issue and its potential impact.
- Steps to reproduce it (proof-of-concept code, requests, or screenshots help).
- The affected URL, endpoint, or component, and any accounts you used.
This policy is also published at /.well-known/security.txt.
What we ask
- Give us a reasonable chance to investigate and fix the issue before disclosing it publicly.
- Do not access, modify, or delete data that is not yours, and do not degrade the service (no denial-of-service or spam testing).
- Only test against your own account or data. Do not attempt to access another customer's workspace.
- Do not use social engineering, phishing, or physical attacks against our staff or infrastructure.
Our commitment
- We will acknowledge your report and keep you informed as we investigate.
- We will work to remediate confirmed issues in a timely manner based on severity.
- We will not pursue legal action against researchers who follow this policy in good faith.
- If you would like, we are glad to credit your responsible disclosure once the issue is resolved.
Keel does not currently run a paid bug-bounty program. This is a coordinated disclosure policy: we welcome and act on good-faith reports.
For how your data is protected and who processes it, see Trust and Subprocessors.