← Back to Home
Krinai

Responsible Disclosure Policy

At Krinai, security is our top priority. We appreciate the work of security researchers who help keep our platform and our clients' data safe. This policy governs our bug bounty and disclosure practices.

Reporting Vulnerabilities

If you identify a security vulnerability in our platform, please disclose it to us responsibly. Reports can be submitted directly to our security team via email at security@krinai.io.

Alternatively, you can participate via our official bug bounty partner page:

Submit Report on Bugcrowd / HackerOne →

Response Timeline SLA

We commit to the following response timeline for all legitimate security reports:

  • Acknowledgment: Within 24 hours of submission.
  • Triage & Severity Classification: Within 72 hours.
  • Remediation/Patch: Within 14 days for CRITICAL vulnerabilities, and 30 days for others.

Scope of Program

In Scope:

  • Krinai SaaS application and frontend (krinai.io, dashboard.krinai.io)
  • Krinai backend APIs (*.krinai.io/api/*)
  • Official integration packages (SDKs for Node, Python, PHP)

Out of Scope:

  • Social engineering, phishing, or physical security attacks against Krinai staff
  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) testing
  • Third-party integrations (e.g. greenhouse.io, lever.co API endpoints directly)

PGP Public Key

For sensitive reports, you may encrypt your communication using our PGP public key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: OpenPGP.js v4.10.10
Comment: https://openpgpjs.org

xsFNBF+7u0EBEADtZqN6J...
... MOCK PGP KEY FOR KRINAI SECURITY DISCLOSURE ...
-----END PGP PUBLIC KEY BLOCK-----