Legal

Vulnerability Disclosure Policy

Last updated: September 26, 2026.2 min readKranth AI, Inc.

We take the security of Kranth and our customers' data seriously. If you've found a vulnerability, we want to hear about it, and we won't take legal action against you for reporting it in good faith.

#How to report

Email [email protected] with:

  • A description of the issue and where you found it (URL, endpoint, or component).
  • Steps to reproduce, or a proof-of-concept.
  • The impact you believe it has.

Encrypt sensitive details if you prefer; ask and we'll share a PGP key. One report per issue. Don't include real customer data in your report.

#What we promise

  • Acknowledgement within 24 hours of receipt.
  • Triage within 5 business days: we'll confirm the issue, ask for anything missing, and give you our assessment.
  • Regular updates while we work a fix, and notice when it ships.
  • Public credit if you want it. We're happy to name you once the fix is live; tell us how you'd like to be credited (or to stay anonymous).
  • No litigation. We will not pursue or support legal action against anyone who reports a vulnerability in good faith under this policy, including under the CFAA or DMCA anti-circumvention provisions. If a third party brings action against you for activity conducted under this policy, we'll make clear it was authorised.

#Ground rules

Good-faith research means:

  • Don't destroy or modify data that isn't yours, and don't access more data than you need to demonstrate the issue. If you encounter customer data, stop and report it.
  • No denial-of-service, resource exhaustion, or load testing against production.
  • No social engineering, phishing, or physical attacks against Kranth staff, contractors, or infrastructure.
  • No automated scanning that degrades service. A handful of manual requests to confirm an issue is fine.
  • Give us a reasonable window to fix before any public disclosure. 90 days is our default; we'll coordinate if you need a different timeline.

#Scope

In scope:

  • kranth.com and the dashboard at app.kranth.ai (plus the legacy app.kranth.com redirect)
  • api.kranth.ai and api.kranth.com
  • gh.kranth.com (GitHub App webhook receiver)
  • aerie.kranth.com (staff admin)
  • status.kranth.com
  • The official Kranth SDKs (Python, TypeScript, Go, Rust)

Out of scope (we'll usually close these as informational):

  • Missing security headers or cookie flags with no demonstrated exploit.
  • Rate-limiting absence on non-sensitive, non-billable endpoints.
  • Reports from automated tools without a working proof-of-concept.
  • Social engineering, and issues requiring an already-compromised device or a physically present attacker.
  • Vulnerabilities in third-party services we use (report those to the vendor; tell us too if customer data is at risk).
  • Self-XSS, clickjacking on pages with no sensitive action, or best-practice suggestions without impact.

#Safe harbor summary

Access only what's necessary, don't harm data or availability, give us time to fix, and we'll treat your research as authorised and welcome. Thank you for helping keep Kranth safe.

Contact: [email protected]
Kranth AI, Inc., c/o Stable, 2810 N Church St STE 89663, Wilmington, DE 19802, United States

You read the whole thing. Most people don't. Thank you.

Questions about this document? [email protected] · Back to the top