Kyro9 is a security company, and we welcome reports from the security-research community. This policy explains how to report a vulnerability responsibly and what you can expect from us.
Email [email protected] with a clear description of the issue, the affected asset or URL, steps to reproduce, and any proof-of-concept. Please encrypt sensitive details on request.
This policy covers Kyro9's public web properties (kyro9.com and its subdomains that we operate). Please do not test third-party services we rely on (e.g. our scheduling or analytics providers) — report those to the respective vendor.
We will not pursue legal action against researchers who act in good faith, comply with this policy, avoid privacy violations and service disruption, and do not access or modify data beyond what is necessary to demonstrate a vulnerability. If in doubt, ask us first.
We aim to acknowledge reports within a few business days, keep you updated on our progress, and credit researchers who wish to be recognized once an issue is resolved.