1. Reporting a vulnerability
We welcome reports of security issues in kott. Please email security@kott.io with enough detail to reproduce the issue — affected URL or feature, steps, and (where relevant) a proof of concept. Our machine-readable contact details are published at /.well-known/security.txt per RFC 9116. [PLACEHOLDER — confirm the security inbox before launch.]
2. What to expect
We aim to acknowledge reports promptly and keep you updated as we investigate and remediate. We may ask for additional information. We do not currently operate a paid bug-bounty program and make no promise of monetary reward; we are grateful for good-faith reports and are happy to credit reporters who wish to be named. [PLACEHOLDER.]
3. Safe harbor (draft)
If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorized, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue quickly. This safe-harbor statement is a draft and does not waive any rights as to third parties. [PLACEHOLDER — exact safe-harbor language pending attorney review.]
4. Scope & good-faith guidelines
Please: test only against accounts and data you own; do not access, modify, or delete other users’ data; avoid privacy violations, service degradation, and destruction of data; and give us a reasonable time to remediate before any public disclosure. Do not run automated scanning that degrades service, and do not attempt social engineering, physical attacks, or denial of service. [PLACEHOLDER.]
5. Out of scope
Reports that typically do not qualify include: findings from automated scanners without a demonstrated impact, missing best-practice headers without a concrete exploit, and issues requiring a compromised device or physical access. [PLACEHOLDER.]