Security

Found a vulnerability? Tell us.

We build security software, so we hold our own systems to the same standard we hold our clients'. If you have found a genuine security issue in anything we run, we want to hear about it — and we will not take legal action against you for reporting it in good faith.

How it works

From report to fix.

You report

Send us the details and evidence through the form below.

We acknowledge

Within 2 business days, with a reference number.

We triage

A severity decision within 10 business days.

We resolve

We fix, tell you when it's live, and credit you if you'd like.

In scope

What we want reported.

  • www.karleesh.com and any karleesh.com subdomain we operate
  • Our public web applications, forms, and APIs
  • The free security scanner and OSINT toolkit
  • Authentication, session handling, and access control flaws
  • Injection, XSS, SSRF, IDOR, and business-logic flaws
  • Exposed credentials, keys, or configuration belonging to us

Out of scope

What we will close without review.

  • Denial of service, load testing, or anything degrading availability
  • Social engineering, phishing, or physical attacks on our staff
  • Findings from automated scanners with no demonstrated impact
  • Missing security headers with no exploitable consequence
  • Self-XSS, clickjacking on static pages, or missing SPF/DMARC on parked domains
  • Vulnerabilities in third-party services we merely use
  • Client systems — those belong to our clients, not to us

Rules of engagement

Test responsibly.

  1. Test only against your own accounts and data.
  2. Stop as soon as you have proof; do not pivot deeper into our systems.
  3. Never access, modify, download, or retain anyone else's data.
  4. Do not run automated scans that generate heavy traffic.
  5. Give us reasonable time to fix before disclosing publicly.
  6. Do not extort. A report conditioned on payment is not a report.

Safe harbour

If you follow the rules on this page, we will treat your research as authorised. We will not pursue civil or criminal action against you, and we will not ask your employer or hosting provider to act against you.

This protection covers our own systems only. It does not extend to client environments, and it does not apply if you access other people's data, disrupt service, or make demands in exchange for the report.

Rewards

We do not run a fixed-price bounty table. Valid reports are rewarded case by case based on severity and quality, and every accepted reporter is offered credit on this page. We will always tell you what to expect during triage rather than after.

Submit

Send us the details.

A clear reproduction is worth more than a long description. Attach screenshots or a short screen recording if it helps us see the issue quickly — reports land directly with our security team.

Not a security issue?

For anything else — support questions, project enquiries, or press — our normal channels are faster.