Coordinated disclosure
Report security issues privately.
Send suspected vulnerabilities to security@kytona.com with enough detail to reproduce the issue. Do not include real memory, credentials, private keys, or third-party personal data.
01
What to include
Include the affected package or service, version, impact, minimal reproduction, and any safe test identifiers. Use synthetic data and redact tokens.
02
What we will do
We will acknowledge the report, assess severity, coordinate a remediation and disclosure timeline, and credit the reporter when requested and appropriate.
03
Safe harbour
Good-faith research that avoids privacy harm, service disruption, data destruction, social engineering, and persistence will not be pursued by Kytona Limited under applicable anti-circumvention law.
04
Scope
The public package, docmancer.dev, authenticated cloud API, dashboard, and official deployment configuration are in scope. Third-party providers and denial-of-service testing are out of scope.