Responsible Disclosure

Guidelines for responsibly reporting potential vulnerabilities.

version 1.2.0 · last updated 2026-02-25

01How to Report

Report suspected vulnerabilities to security@kettlelogic.example and include affected URLs, reproduction steps, impact, and any proof-of-concept details.

02Testing Expectations

Only perform non-destructive testing. Do not access another user’s data, degrade service availability, or use social engineering or physical intrusion methods.

03Disclosure Process

Kettle Logic will acknowledge receipt, investigate, and coordinate remediation timelines. Public disclosure should wait until fixes are deployed or approved.

04Safe Harbor

Kettle Logic will not pursue legal action for good-faith research performed under this policy and applicable law. Researchers must promptly stop activity upon request.

05PGP Key Placeholder

-----BEGIN PGP PUBLIC KEY BLOCK----- Version: Placeholder Comment: Replace with production key mQENBGPLACEHOLDERBCAD... -----END PGP PUBLIC KEY BLOCK-----

Questions about this policy? Contact us →

Let’s talk shop

Let’s build the system your operations actually need.

Custom software, intelligent workflows, and governed AI — designed around how your team really runs, not a template.

Direct founder access · fixed-scope pilots · measurable outcomes