Security
If you believe you've found a security issue in Kindroid, please report it to us privately. We review every report.
How to report
Email [email protected] with the subject "Security report". Please include:
- The affected URL, endpoint or app version
- Steps to reproduce
- What an attacker could do with it
A short, specific report is more useful than a long one. Scanner output without a demonstrated impact will usually be closed without action.
Scope
kindroid.ai and its subdomains, and the Kindroid iOS and Android apps.
The following are generally not accepted:
- Denial of service, load testing, or spam
- Social engineering, phishing, or physical attacks
- Missing headers or best-practice suggestions without a working exploit
- Issues in third-party services we use
- Rate limiting on endpoints where it has no security impact
Testing rules
- Only use accounts you own. Don't access, modify, or keep other users' data.
- If you encounter user data, stop and report it.
- Don't degrade the service for other users.
- Don't publish or share details of an issue without our written agreement.
Rewards
We don't run a paid bug bounty program. In some cases we may send a thank-you for a verified, significant report. Any reward is at our sole discretion, based on the impact we verify, and is not negotiable.
Reports that come with demands for payment, deadlines, or threats of disclosure are not eligible for any reward.
Our commitment
If you follow this policy in good faith, we'll acknowledge your report, work to fix valid issues, and won't pursue action against you for your research.