We take the security of Kranth and our customers' data seriously. If you've found a vulnerability, we want to hear about it, and we won't take legal action against you for reporting it in good faith.
#How to report
Email [email protected] with:
- A description of the issue and where you found it (URL, endpoint, or component).
- Steps to reproduce, or a proof-of-concept.
- The impact you believe it has.
Encrypt sensitive details if you prefer; ask and we'll share a PGP key. One report per issue. Don't include real customer data in your report.
#What we promise
- Acknowledgement within 24 hours of receipt.
- Triage within 5 business days: we'll confirm the issue, ask for anything missing, and give you our assessment.
- Regular updates while we work a fix, and notice when it ships.
- Public credit if you want it. We're happy to name you once the fix is live; tell us how you'd like to be credited (or to stay anonymous).
- No litigation. We will not pursue or support legal action against anyone who reports a vulnerability in good faith under this policy, including under the CFAA or DMCA anti-circumvention provisions. If a third party brings action against you for activity conducted under this policy, we'll make clear it was authorised.
#Ground rules
Good-faith research means:
- Don't destroy or modify data that isn't yours, and don't access more data than you need to demonstrate the issue. If you encounter customer data, stop and report it.
- No denial-of-service, resource exhaustion, or load testing against production.
- No social engineering, phishing, or physical attacks against Kranth staff, contractors, or infrastructure.
- No automated scanning that degrades service. A handful of manual requests to confirm an issue is fine.
- Give us a reasonable window to fix before any public disclosure. 90 days is our default; we'll coordinate if you need a different timeline.
#Scope
In scope:
kranth.comand the dashboard atapp.kranth.ai(plus the legacyapp.kranth.comredirect)api.kranth.aiandapi.kranth.comgh.kranth.com(GitHub App webhook receiver)aerie.kranth.com(staff admin)status.kranth.com- The official Kranth SDKs (Python, TypeScript, Go, Rust)
Out of scope (we'll usually close these as informational):
- Missing security headers or cookie flags with no demonstrated exploit.
- Rate-limiting absence on non-sensitive, non-billable endpoints.
- Reports from automated tools without a working proof-of-concept.
- Social engineering, and issues requiring an already-compromised device or a physically present attacker.
- Vulnerabilities in third-party services we use (report those to the vendor; tell us too if customer data is at risk).
- Self-XSS, clickjacking on pages with no sensitive action, or best-practice suggestions without impact.
#Safe harbor summary
Access only what's necessary, don't harm data or availability, give us time to fix, and we'll treat your research as authorised and welcome. Thank you for helping keep Kranth safe.
Contact: [email protected]
Kranth AI, Inc., c/o Stable, 2810 N Church St STE 89663, Wilmington, DE 19802, United States