Responsible Disclosure
Overview
Valtio Inc. is committed to the security of Koffyr and the data of our customers. If you have discovered a security vulnerability in any Koffyr system, we want to hear from you.
This policy describes how to report vulnerabilities, what we commit to in response, and what behavior is within and outside the scope of good-faith security research.
How to Report
Send your report to security@koffyr.com. Please include:
- A description of the vulnerability and the potential impact
- Reproduction steps (proof-of-concept, screenshots, or video if applicable)
- Affected URL(s), endpoint(s), or component(s)
- Whether you have disclosed or plan to disclose the issue elsewhere
We acknowledge all reports within 5 business days. We will keep you informed as we investigate and will notify you when the issue is resolved.
Safe Harbor
We consider good-faith security research to be valuable and will not take legal action against researchers who:
- Report the issue to us promptly and give us reasonable time to remediate before disclosing publicly (90-day coordinated disclosure window)
- Avoid accessing, modifying, or deleting data beyond what is minimally necessary to demonstrate the vulnerability
- Do not exploit the vulnerability for any purpose other than demonstrating its existence
- Do not conduct attacks that affect the availability of our systems (no DoS or volumetric attacks)
- Do not engage in social engineering of Valtio staff or customers
- Do not conduct physical attacks against Valtio facilities or hardware
If you inadvertently access data beyond what is necessary to confirm a vulnerability during good-faith testing, we will not pursue legal action provided you disclose this to us promptly and destroy the data.
Scope
In scope:
- koffyr.com (marketing site)
- app.koffyr.com (Koffyr application)
- API surfaces (api.koffyr.com and related subdomains)
- Authentication and authorization controls
- Data access and tenant isolation
Out of scope:
- Denial of service (DoS) or volumetric attacks
- Social engineering of Valtio staff or customers
- Physical attacks against Valtio facilities or hardware
- Attacks against third-party services (AWS, Cloudflare, Stripe, etc.)
- Automated scanner output without a demonstrated vulnerability
- Issues already publicly known or without security impact
- Self-XSS (requiring a user to paste code into their own browser)
- Rate limiting or brute-force on non-authentication endpoints
Coordinated Disclosure
We request a 90-day coordinated disclosure window from the date we confirm receipt of a valid report. During this window, we ask that you do not disclose the vulnerability publicly or to third parties.
We aim to confirm vulnerabilities and provide an initial remediation timeline within 10 business days of receiving a report. We will work with you to agree on a disclosure date, especially for high-severity issues.
We may thank researchers publicly (with their permission) for valid reports that help improve Koffyr's security.
Bug Bounty
We do not currently operate a paid bug bounty program. We may thank researchers publicly with their permission for valid, in-scope reports.
Contact
Security reports: security@koffyr.com
General legal inquiries: legal@koffyr.com
Privacy inquiries: privacy@koffyr.com