Trust

Vulnerability disclosure policy

We take the security of Keel and our customers' data seriously. If you believe you have found a security vulnerability, we want to hear from you, and we will work with you to understand and resolve it quickly.

How to report

Email [email protected] with:

  • A clear description of the issue and its potential impact.
  • Steps to reproduce it (proof-of-concept code, requests, or screenshots help).
  • The affected URL, endpoint, or component, and any accounts you used.

This policy is also published at /.well-known/security.txt.

What we ask

  • Give us a reasonable chance to investigate and fix the issue before disclosing it publicly.
  • Do not access, modify, or delete data that is not yours, and do not degrade the service (no denial-of-service or spam testing).
  • Only test against your own account or data. Do not attempt to access another customer's workspace.
  • Do not use social engineering, phishing, or physical attacks against our staff or infrastructure.

Our commitment

  • We will acknowledge your report and keep you informed as we investigate.
  • We will work to remediate confirmed issues in a timely manner based on severity.
  • We will not pursue legal action against researchers who follow this policy in good faith.
  • If you would like, we are glad to credit your responsible disclosure once the issue is resolved.

Keel does not currently run a paid bug-bounty program. This is a coordinated disclosure policy: we welcome and act on good-faith reports.

For how your data is protected and who processes it, see Trust and Subprocessors.