Responsible Disclosure
How to report a vulnerability and what to expect from KONDWIT in return.
How to report
Email security@kondwit.com with the issue. Include affected endpoint(s), a clear description, a reproducible proof-of-concept, and any suggested fix. We do not currently publish a PGP key, so we cannot offer encrypted email intake — if you need an encrypted channel for a sensitive report, say so in a first message and we will arrange one with you.
Active exploitation or severe vulnerabilities: same email with subject line INCIDENT: <summary> — we ack within 1 hour for critical reports.
Our commitments
- First response: within 1 business day of report.
- Triage decision: within 5 business days (in-scope / out / duplicate / severity).
- Remediation SLAs: Critical 7 days · High 30 days · Medium 90 days · Low best-effort.
- Coordinated disclosure: 90-day embargo from report (extendable for complex fixes).
- Customer notification: per our breach notification procedure (within 72 hours of confirmed personal-data exposure).
Bug bounty program
Roadmap — not operating today. KONDWIT runs no bug bounty. A private, invite-only program on HackerOne is designed on paper, but no platform account has been opened and no researcher has been invited, so there is no bounty to claim and no reward table in force. Reports sent to the address above are still triaged and fixed under the commitments listed here. The program design covers the intended scope, rules of engagement, and rewards.
Penetration testing
No external penetration test has been performed on KONDWIT to date. The intended cadence is an annual external test plus ad-hoc tests on major changes, and a sanitized summary published here after each engagement — but the first engagement has not been booked, so there is no summary and no report to request. If a recent pen-test report is a gating requirement for your procurement today, KONDWIT does not meet it.
Out of scope
- kondwit.com marketing site
- Third-party services (report to vendor directly)
- Social engineering of personnel
- Physical attacks
- DDoS / volumetric attacks
- Theoretical vulnerabilities without proof-of-concept
security.txt
Our RFC 9116 security.txt is published at /.well-known/security.txt.