Responsible Disclosure Policy

Last updated: July 22, 2026

Kyro9 is a security company, and we welcome reports from the security-research community. This policy explains how to report a vulnerability responsibly and what you can expect from us.

How to report

Email [email protected] with a clear description of the issue, the affected asset or URL, steps to reproduce, and any proof-of-concept. Please encrypt sensitive details on request.

Scope

This policy covers Kyro9's public web properties (kyro9.com and its subdomains that we operate). Please do not test third-party services we rely on (e.g. our scheduling or analytics providers) — report those to the respective vendor.

Safe harbor

We will not pursue legal action against researchers who act in good faith, comply with this policy, avoid privacy violations and service disruption, and do not access or modify data beyond what is necessary to demonstrate a vulnerability. If in doubt, ask us first.

Please do

  • Give us reasonable time to investigate and remediate before any public disclosure.
  • Make a good-faith effort to avoid data destruction, privacy violations, and degradation of service.
  • Only interact with accounts you own or have explicit permission to test.

Please don't

  • Run denial-of-service, spam, or social-engineering attacks against our staff or users.
  • Access, download, or modify data that isn't yours.
  • Publicly disclose an issue before we've had a chance to address it.

What to expect

We aim to acknowledge reports within a few business days, keep you updated on our progress, and credit researchers who wish to be recognized once an issue is resolved.

Contact

[email protected]