Security
Report a security vulnerability
Found a vulnerability in a KARIGUARD site or service? Get in touch. This page explains how, and what you can expect from us.
We are a cybersecurity integrator. It would be poor form not to apply to our own services what we recommend to our clients: a clear way in for reports, and an answer.
How to report
Write to contact@kariguard.com with “security” in the subject line. So we can act quickly, please include:
- the exact address concerned, and when you observed the issue;
- the steps to reproduce it;
- what you believe the flaw allows someone to do;
- how you would like to be credited, if at all.
A screenshot or a short recording is often worth more than a long description. Please don’t attach anyone else’s data — describe it rather than send it.
What we commit to
- acknowledging your report within 3 working days;
- telling you whether we accept the finding, and why if we don’t;
- keeping you posted until it is fixed;
- crediting you publicly if you want, or respecting your anonymity.
What we ask of you
These rules aren’t red tape: they are what separates security research from intrusion.
- Don’t access anyone else’s data. If a flaw gives you access to information that isn’t yours, stop there and describe what you could have reached.
- Don’t degrade the service. No load testing, no denial of service, no deleting or altering data.
- No social engineering — not against our team, our clients, or our suppliers.
- Give us time to fix it before publishing. We’ll agree a reasonable timeframe together.
Scope
This policy covers:
- this website and its subdomains;
- services operated directly by KARIGUARD.
It does not cover our partners’ and suppliers’ services, which have their own procedures — report those to them directly. Nor does it cover our clients’ infrastructure, which isn’t ours and for which we cannot grant you any authorisation.
No bug bounty
We don’t offer financial rewards. We’d rather say so plainly than let you hope otherwise: your report will be taken seriously and you’ll be credited if you wish, but there is no payment attached.
Safe harbour
If you follow the rules above, act in good faith, and report what you find without disclosing or exploiting it, KARIGUARD will take no action against you in respect of that research.
This commitment covers what KARIGUARD controls. It does not bind our clients, our hosting providers or any third party, and it does not exempt you from applicable law.
Where to find this
The /.well-known/security.txt file, in RFC 9116 format, carries the contact address and points back to this page. It is the first place an automated tool will look.
