Security
Found a vulnerability? Tell us.
We build security software, so we hold our own systems to the same standard we hold our clients'. If you have found a genuine security issue in anything we run, we want to hear about it — and we will not take legal action against you for reporting it in good faith.
How it works
From report to fix.
You report
Send us the details and evidence through the form below.
We acknowledge
Within 2 business days, with a reference number.
We triage
A severity decision within 10 business days.
We resolve
We fix, tell you when it's live, and credit you if you'd like.
In scope
What we want reported.
- www.karleesh.com and any karleesh.com subdomain we operate
- Our public web applications, forms, and APIs
- The free security scanner and OSINT toolkit
- Authentication, session handling, and access control flaws
- Injection, XSS, SSRF, IDOR, and business-logic flaws
- Exposed credentials, keys, or configuration belonging to us
Out of scope
What we will close without review.
- Denial of service, load testing, or anything degrading availability
- Social engineering, phishing, or physical attacks on our staff
- Findings from automated scanners with no demonstrated impact
- Missing security headers with no exploitable consequence
- Self-XSS, clickjacking on static pages, or missing SPF/DMARC on parked domains
- Vulnerabilities in third-party services we merely use
- Client systems — those belong to our clients, not to us
Rules of engagement
Test responsibly.
- Test only against your own accounts and data.
- Stop as soon as you have proof; do not pivot deeper into our systems.
- Never access, modify, download, or retain anyone else's data.
- Do not run automated scans that generate heavy traffic.
- Give us reasonable time to fix before disclosing publicly.
- Do not extort. A report conditioned on payment is not a report.
Safe harbour
If you follow the rules on this page, we will treat your research as authorised. We will not pursue civil or criminal action against you, and we will not ask your employer or hosting provider to act against you.
This protection covers our own systems only. It does not extend to client environments, and it does not apply if you access other people's data, disrupt service, or make demands in exchange for the report.
Rewards
We do not run a fixed-price bounty table. Valid reports are rewarded case by case based on severity and quality, and every accepted reporter is offered credit on this page. We will always tell you what to expect during triage rather than after.
Submit
Send us the details.
A clear reproduction is worth more than a long description. Attach screenshots or a short screen recording if it helps us see the issue quickly — reports land directly with our security team.
Not a security issue?
For anything else — support questions, project enquiries, or press — our normal channels are faster.