Coordinated disclosure

Report security issues privately.

Send suspected vulnerabilities to security@kytona.com with enough detail to reproduce the issue. Do not include real memory, credentials, private keys, or third-party personal data.

01

What to include

Include the affected package or service, version, impact, minimal reproduction, and any safe test identifiers. Use synthetic data and redact tokens.

02

What we will do

We will acknowledge the report, assess severity, coordinate a remediation and disclosure timeline, and credit the reporter when requested and appropriate.

03

Safe harbour

Good-faith research that avoids privacy harm, service disruption, data destruction, social engineering, and persistence will not be pursued by Kytona Limited under applicable anti-circumvention law.

04

Scope

The public package, docmancer.dev, authenticated cloud API, dashboard, and official deployment configuration are in scope. Third-party providers and denial-of-service testing are out of scope.