01In scope
Any system that serves Kirky, including:
- kirkyapp.com and its subdomains, including the customer portal
- The widget script and SDK served from cdn.kirkyapp.com
- The Kirky APIs the widget and the portal call
- The open-source database connector
02Out of scope
Please don’t test or report the following:
- Denial of service, load testing or anything that degrades the service for others
- Social engineering, phishing or physical attacks against our team or customers
- Systems of our customers, including the apps where Kirky is embedded
- Reports from automated scanners without a demonstrated impact
- Missing security headers or best-practice notes with no exploitable consequence
- Getting an AI answer to say something odd, unless it crosses a workspace boundary, leaks data or bypasses a permission
03How to report
Email security@kirkyapp.com, in English or Spanish. If the details are sensitive, ask us for an encryption key in your first message and we’ll reply with one.
A good report includes:
- What you found and why it matters
- The steps to reproduce it, with the URLs, requests or payloads involved
- The accounts or workspaces you used (use your own test workspace, never someone else’s)
- How you would like to be credited, if at all
04While you test
- Only access data you own. If you reach someone else’s data, stop, don’t keep or share it, and tell us.
- Don’t change or delete data that isn’t yours.
- Give us a reasonable chance to fix the issue before you disclose it publicly.
05What we commit to
When you report in good faith, we will:
- Acknowledge your report and tell you who is handling it
- Keep you informed while we investigate and fix it
- Tell you when it is resolved, and agree with you on the timing of any public disclosure
- Credit you publicly if you want us to
06Safe harbor
If you make a good-faith effort to follow this policy, we consider your research authorized, we won’t pursue or support legal action against you for it, and if a third party takes action against you over research that followed this policy, we will make it known that you acted with our authorization.
07Rewards
We don’t run a bug bounty program yet. We are grateful for every report, and we will say so publicly if you would like.
Contact: mailto:security@kirkyapp.com Expires: 2027-09-30T00:00:00.000Z Preferred-Languages: es, en Policy: https://kirkyapp.com/en/security/disclosure Canonical: https://kirkyapp.com/.well-known/security.txt