Vulnerability disclosure
Last updated: 26 August 2026
Report security issues to [email protected]. Do not open a public GitHub issue, pull request, or discussion for a vulnerability. This page is the policy linked from /.well-known/security.txt. It is not a bug bounty, not a contractual SLA, and not a promise that every report receives a CVE.
1. How to report
Email [email protected] from an address we can reply to. Include, as far as you can:
- the affected product (cloud service, daemon, encryption engine, language package, operator);
- version, commit, or release if you have it;
- a description of the issue and why it matters;
- steps to reproduce, or a proof of concept that does not harm other customers;
- whether you have already told anyone else.
We do not currently publish a PGP key. If you need a more private channel than email, say so in the first message and we will arrange one.
2. Scope
In scope
- the managed Kryptic cloud service at kryptic.dev and its API hosts;
- open-source repositories under github.com/dev-kryptic: encryption engines, daemon and CLI, language packages, Kubernetes operator;
- published daemon installers and packages we ship.
Out of scope
- self-hosted deployments you or a customer operate (report those to the operator);
- third-party identity providers, Stripe, email vendors, and other subprocessors;
- denial of service, spam, or volumetric flooding;
- social engineering, phishing, or physical access;
- findings that require a stolen vault passphrase, recovery code, or machine-identity secret;
- missing best-practice hardening that is not a vulnerability;
- issues only present on unreleased code that has never been tagged or deployed.
3. What we ask you not to do
- do not access another customer's data, even to prove a point;
- do not degrade the service for other users;
- do not run automated scanners against production at a volume that looks like an attack;
- do not demand payment before describing the issue.
Good-faith research that stays inside this policy will not be the subject of a legal complaint from Theka.dev SINGLE MEMBER P.C. That is not permission to break the law, and it is not a waiver of rights we cannot waive.
4. Response targets (not an SLA)
We are a small team. These are targets, not contractual response times, and they pause on Greek public holidays.
- Acknowledgement: we aim to reply within five business days.
- Initial assessment: we aim to say whether we accept the issue within ten business days of acknowledgement.
- Fix date: none promised. We will tell you what we know.
There is no paid bug bounty today. If you want to be credited by name, say so and we will include you when we publish a fix note. We do not currently keep a public hall of fame.
5. CVE coordination
Kryptic is not a CVE Numbering Authority. We do not assign CVE IDs. We do not invent IDs, and we do not request a CVE for every report.
When a confirmed vulnerability in a released, supported component warrants a CVE:
- Open source (encryption engines, daemon, language packages, Kubernetes operator): we open a GitHub Security Advisory on the affected repository and request a CVE through GitHub. GitHub's CNA assigns the ID.
- Cloud platform (proprietary): we request a CVE from MITRE, or from another CNA that will take the issue, if a CVE is the right tool. Assignment is theirs.
We will not request a CVE for:
- issues that only exist on unreleased code;
- theoretical weaknesses with no practical impact we can describe;
- bugs in third-party software we do not ship;
- misconfiguration of a self-hosted instance;
- missing hardening that is not a vulnerability.
We publish an advisory when a fix is available, or on a date agreed with the reporter. We ask that you do not disclose the issue publicly until then, or until 90 days after our first acknowledgement, whichever comes first. If we go silent, you are not bound by that request. This is a request, not a contract.
6. Encryption and "zero-knowledge"
Secret values are end-to-end encrypted as described on the security page. We do not use the phrase "zero-knowledge" until an independent cryptographic review is published. Reports that the server can read secret values, if true, are in scope and high priority.
7. Contact
Security: [email protected]
Everything else: [email protected]
Operator: Theka.dev SINGLE MEMBER P.C., GEMI 194371006000. This policy can change. The copy on this page is the current one.