Vulnerability Disclosure Policy
At Kraaft, the security of our users and their data is a priority. We know that no system is perfect, and we welcome help from security researchers and anyone who identifies a vulnerability in our services. This policy describes how to report a vulnerability to us responsibly and what you can expect from us in return.
Safe Harbor Commitment
Kraaft commits to not pursuing legal action or reporting to the authorities any individual who discovers and reports a vulnerability in good faith and in compliance with this policy. We consider this research an authorized and welcome contribution.
In practical terms, as long as you comply with this policy:
Do not publish, share, or store any information related to the vulnerability (posts, videos, forums, social media, etc.).
- We will not initiate any legal action against you regarding your research.
- We will not consider your activity a violation of our terms of service.
- We will work with you to understand and resolve the issue quickly.
Do not publicly disclose the vulnerability, before or after it is fixed, without our prior consent (see "Coordinated Disclosure").
If legal action is initiated by a third party against you for activity conducted in accordance with this policy, we will take the necessary steps to make it known that your actions were authorized.
Do not run aggressive automated scanners, perform denial-of-service attacks, or send spam.
Scope
Do not attempt to access, modify, or delete other users' accounts or data.
This policy applies to the following assets operated by Kraaft:
Do not compromise the confidentiality, integrity, or availability of our services or data.
- The web application: app.kraaft.co
- The public API and its documentation: developers.kraaft.co
- The marketing website: www.kraaft.com
- Kraaft mobile applications: iOS (App Store) and Android (Google Play)
Collect only the information strictly necessary to demonstrate the vulnerability.
Out of scope
Conduct your research only within the scope defined above.
The following are not covered by this policy:
We ask that you:
- The underlying hosting infrastructure (Google Cloud Platform), managed by our hosting provider.
- Third-party services and platforms we use. Please report these directly to the relevant vendors.
- Any action targeting our employees, offices, or internal systems (social engineering, phishing, physical access).
Types of reports we do not accept (unless there is concrete proof of exploitability and real impact):
- Missing HTTP security headers or TLS/SSL configuration best practices, without a demonstration of impact.
- Raw output from automated scanners without a proof of concept (PoC).
- Self-XSS, or XSS/HTML injection without demonstrable impact.
- Lack of rate limiting, brute-force attacks.
- CSRF on unauthenticated forms or forms without sensitive actions; logout CSRF.
- Email spoofing / SPF, DKIM, or DMARC issues.
- User enumeration (email addresses, usernames, etc.).
- Version disclosure / banners, or public information already exposed.
- Clickjacking on pages without sensitive actions; tabnabbing. Use of a library known to be vulnerable, without proof of exploitability.
- Vulnerabilities affecting only obsolete or unpatched browsers.
- Any attack requiring physical access or a man-in-the-middle (MITM) interceptor on the victim's device.
- Any action that could degrade service availability (DoS / DDoS).
Rules to follow
We ask that you:
- Conduct your research only within the scope defined above.
- Collect only the information strictly necessary to demonstrate the vulnerability.
- Do not compromise the confidentiality, integrity, or availability of our services or data.
- Do not attempt to access, modify, or delete other users' accounts or data.
- Do not perform aggressive automated scans, denial-of-service attacks, or mass mailings (spam).
- Do not publicly disclose the vulnerability, before or after correction, without our prior consent (see "Coordinated Disclosure").
- Do not publish, share, or store information related to the vulnerability (posts, videos, forums, social media, etc.).
Personal data: if, during your research, you encounter personal data (belonging to a user, a customer, or Kraaft), you must immediately cease your activity, refrain from copying or storing it, and notify us without delay. This requirement stems from our obligations under the GDPR (Regulation (EU) 2016/679).
How to report a vulnerability to us
- Send your report via email to security@kraaft.co. Our security contact point is also referenced in our security.txt file ( https://www.kraaft.com/.well-known/security.txt ).
- Describe the vulnerability in as much detail as possible: affected component, reproduction steps, proof of concept, potential impact, and your contact details.
- Provide valid contact information (email): we may need to reach out to you if further details are required.
- Treat all information regarding the vulnerability as confidential until it is resolved.
Our commitments
If your report complies with this policy, Kraaft commits to:
- Acknowledge receipt of your report within 15 business days.
- Assess the vulnerability, confirm its validity, and keep you updated on the progress of the resolution.
- Remediate confirmed vulnerabilities based on their severity level, in accordance with our internal remediation timelines:
- Critical: within 14 days
- High: within 30 days
- Medium: within 60 days
- Low: between 90 to 180 days
- Notify you once the fix has been deployed.
Coordinated disclosure
We practice coordinated disclosure. We ask that you do not make any information about the vulnerability public until it has been fixed and there is mutual agreement on the timing and content of any communication. We commit to working with you within a reasonable timeframe.
Recognition
Kraaft does not offer a financial reward program (bug bounty). However, with your consent, we would be happy to publicly acknowledge your contribution once the vulnerability has been patched. You may also choose to remain anonymous.
Reporting to ANSSI
In France, Article L2321-4 of the Defense Code allows, under certain conditions, for the good-faith reporting of a vulnerability to ANSSI (the National Cybersecurity Agency of France), which can protect the reporter's identity. This option remains available as an alternative to reporting directly to Kraaft.
Miscellaneous
Kraaft reserves the right to accept or reject any vulnerability report at its discretion. Only the first reporter of a valid vulnerability will be recognized; duplicate reports will not be considered. A single vulnerability present in multiple locations within the same application is considered a single vulnerability.
By reporting a vulnerability to us, you acknowledge that your actions are voluntary, without expectation of financial or other compensation, and are subject to this policy.
Last updated : @August 24, 2026



















