Skip to content
kirky
Responsible disclosure

Found a vulnerability? Tell us first.

We welcome reports from security researchers and customers. If you follow this policy, we will work with you and won’t pursue legal action.

Updated:
Report tosecurity@kirkyapp.com

01In scope

Any system that serves Kirky, including:

  • kirkyapp.com and its subdomains, including the customer portal
  • The widget script and SDK served from cdn.kirkyapp.com
  • The Kirky APIs the widget and the portal call
  • The open-source database connector

02Out of scope

Please don’t test or report the following:

  • Denial of service, load testing or anything that degrades the service for others
  • Social engineering, phishing or physical attacks against our team or customers
  • Systems of our customers, including the apps where Kirky is embedded
  • Reports from automated scanners without a demonstrated impact
  • Missing security headers or best-practice notes with no exploitable consequence
  • Getting an AI answer to say something odd, unless it crosses a workspace boundary, leaks data or bypasses a permission

03How to report

Email security@kirkyapp.com, in English or Spanish. If the details are sensitive, ask us for an encryption key in your first message and we’ll reply with one.

A good report includes:

  • What you found and why it matters
  • The steps to reproduce it, with the URLs, requests or payloads involved
  • The accounts or workspaces you used (use your own test workspace, never someone else’s)
  • How you would like to be credited, if at all

04While you test

  • Only access data you own. If you reach someone else’s data, stop, don’t keep or share it, and tell us.
  • Don’t change or delete data that isn’t yours.
  • Give us a reasonable chance to fix the issue before you disclose it publicly.

05What we commit to

When you report in good faith, we will:

  • Acknowledge your report and tell you who is handling it
  • Keep you informed while we investigate and fix it
  • Tell you when it is resolved, and agree with you on the timing of any public disclosure
  • Credit you publicly if you want us to

06Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorized, we won’t pursue or support legal action against you for it, and if a third party takes action against you over research that followed this policy, we will make it known that you acted with our authorization.

07Rewards

We don’t run a bug bounty program yet. We are grateful for every report, and we will say so publicly if you would like.

Our security.txt
Contact: mailto:security@kirkyapp.com
Expires: 2027-09-30T00:00:00.000Z
Preferred-Languages: es, en
Policy: https://kirkyapp.com/en/security/disclosure
Canonical: https://kirkyapp.com/.well-known/security.txt

See it inside a real app.

The demo is a sample app with Kirky already installed. Ask it anything you’d ask in yours.