LEGAL & TRUST
Vulnerability Disclosure Policy
Report suspected KRAVIA vulnerabilities privately and avoid harm. We support good-faith reporting within the scope below, but do not authorize testing third-party systems, accessing other customers' data or causing disruption. No automatic monetary bounty is offered.
2
Permitted conduct
Limit testing to what is reasonably necessary to demonstrate the issue safely. Use the least intrusive proof of concept and stop once the vulnerability is established. Avoid persistence, lateral movement, privilege expansion beyond a minimal proof or repeated exploitation.
If you encounter another person's information, stop accessing it, do not copy or share it, and report the circumstances through the secure reporting channel. Where a minimal redacted example is necessary, agree a safe way to provide it. Do not download a database to prove that it is downloadable.
4
How to report
Email security@kraviaprivatelimited.com with the affected KRAVIA asset, a description, safe reproduction steps, expected impact, relevant timestamps and a way to contact you. Include only the minimum evidence needed. Do not send credentials, complete personal records or a dangerous attachment without an agreed secure method.
We do not publish an encryption key or claim an encrypted intake mechanism until it actually exists and is verified. Request an appropriate transfer method before sending particularly sensitive evidence.
5
Triage and communication
We assess the report, determine scope and severity, seek clarification when needed, and work toward appropriate remediation. Duplicate or non-exploitable reports may be closed with an explanation where feasible. General corporate acknowledgement targets are not a guaranteed engineering remediation deadline; actual timing depends on risk, dependencies and verification.
We aim to keep a good-faith reporter informed of material progress and coordinate an appropriate disclosure date. No universal fixed public-release period is imposed by this draft. A critical risk may require immediate containment or legally required notification before the underlying issue is fully resolved.
6
Good-faith treatment
Where research complies with this Policy and applicable authorization, KRAVIA will not initiate legal action merely for that authorized research or deliberately threaten a reporter for bringing a valid issue to our attention. This commitment concerns KRAVIA's own conduct; it does not bind authorities, customers or other providers or confer immunity from law.
If a mistake occurs, stop, minimize harm and report it promptly. We assess the circumstances rather than treating every unintentional misstep as malicious conduct. Activity materially outside the scope is not retroactively authorized merely because a report is later submitted.
7
Disclosure, credit and information handling
Do not publicly disclose a vulnerability or identifying evidence before a safe coordinated approach is agreed, except where a legal obligation requires otherwise. We do not use confidentiality to suppress necessary notifications or indefinitely conceal a material user risk.
Attribution, if offered and approved, requires the reporter's consent to the name or alias used. We protect contact details and report material according to the Privacy and Retention Policies. Recognition does not constitute a certification, employment relationship or guaranteed payment.
8
Changes and contact
The current target scope and testing conditions govern prospective testing. Scope changes must be clear; they do not erase responsibilities for an already reported issue. For uncertainty or suspected active exploitation, contact security@kraviaprivatelimited.com rather than increasing testing intensity.