At Krinai, security is our top priority. We appreciate the work of security researchers who help keep our platform and our clients' data safe. This policy governs our bug bounty and disclosure practices.
If you identify a security vulnerability in our platform, please disclose it to us responsibly. Reports can be submitted directly to our security team via email at security@krinai.io.
Alternatively, you can participate via our official bug bounty partner page:
Submit Report on Bugcrowd / HackerOne →We commit to the following response timeline for all legitimate security reports:
In Scope:
Out of Scope:
For sensitive reports, you may encrypt your communication using our PGP public key:
-----BEGIN PGP PUBLIC KEY BLOCK----- Version: OpenPGP.js v4.10.10 Comment: https://openpgpjs.org xsFNBF+7u0EBEADtZqN6J... ... MOCK PGP KEY FOR KRINAI SECURITY DISCLOSURE ... -----END PGP PUBLIC KEY BLOCK-----