Company Policies

The principles that guide every team at Kriko. From how we hire and protect data to how we uphold quality and sustainability.

Vulnerability Disclosure Policy

Purpose

This policy sets out the principles for the responsible and secure reporting of vulnerabilities identified in systems owned or managed by Kriko. Kriko recognizes the contribution that independent security researchers can make to identifying vulnerabilities before they are exploited and supports good-faith security research.

Scope

This policy applies to the following Kriko digital assets:

  • kriko.io and subdomains managed by Kriko.
  • Publicly accessible web applications and tools operated by Kriko.
  • APIs and other internet-facing services operated by Kriko.
  • Other digital systems explicitly identified by Kriko as being within the scope of this policy.

Third-party platforms, customer systems, customer advertising accounts, external SaaS services and other third-party infrastructure that Kriko does not own or control are outside the scope of this policy.

If there is any uncertainty as to whether a system is within scope, Kriko should be contacted before any testing is conducted.

Reporting a Vulnerability

Identified vulnerabilities should be reported to:

security@kriko.io

Reports should include, where possible, the following information:

  • The affected URL, application, system or service.
  • A description of the vulnerability and its potential impact.
  • The steps required to reproduce the vulnerability.
  • Screenshots, request and response examples, proof-of-concept information, where available.
  • Any other technical information that may assist in evaluating the issue.

Reports should not include personal data, user information, passwords, customer data or other confidential information that is not necessary to assess the vulnerability.

Responsible Security Research

Security research must be conducted in good faith and solely for the purpose of identifying and reporting vulnerabilities.

  • Activities that may adversely affect the availability or performance of Kriko systems must be avoided.
  • Only the minimum level of testing required to demonstrate the vulnerability should be performed.
  • Testing must stop immediately if personal data, customer information, credentials or other confidential information is accessed.
  • Data accessed during testing must not be modified, deleted, downloaded, disclosed or used for any other purpose.
  • Once sufficient evidence has been obtained to demonstrate the existence of the vulnerability, no attempt should be made to gain additional access.

Prohibited Activities

This policy does not authorize the following activities:

  • Denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks.
  • High-volume automated requests that may affect system performance or availability.
  • Credential stuffing, password spraying or large-scale brute-force attacks.
  • Social engineering, phishing, impersonation or physical security testing.
  • Targeting Kriko employees, customers, business partners or other third parties.
  • Use of malware, ransomware, backdoors or persistent access mechanisms.
  • Accessing, downloading, modifying or deleting more data than is necessary to demonstrate a vulnerability.
  • Testing third-party systems that Kriko does not own or control.
  • Public disclosure of an identified vulnerability without giving Kriko a reasonable period of time to remediate the issue.

Good-Faith Research and Authorization

Kriko supports good-faith security research conducted in accordance with this policy.

Researchers are expected to limit their testing to systems within the scope of this policy, avoid unnecessary harm, perform only the actions required to verify the vulnerability and report identified vulnerabilities responsibly.

To the extent permitted by applicable law, Kriko does not intend to initiate legal proceedings against researchers solely for security research conducted in good faith and in accordance with this policy.

This approach does not apply to activities that violate applicable laws, affect third-party systems or exceed the scope of this policy.

Evaluation of Reports

Kriko evaluates received vulnerability reports to determine their validity, severity and potential impact.

  • Additional technical information or reproduction steps may be requested from the researcher where necessary.
  • Confirmed vulnerabilities are prioritized according to their severity, exploitability and potential impact.
  • Appropriate corrective and preventive security measures are implemented.
  • Remediation timelines may vary depending on the technical complexity and operational impact of the issue.

Coordinated Disclosure

Researchers should provide Kriko with a reasonable period of time to investigate and remediate identified vulnerabilities before publicly disclosing them.

Technical information that could facilitate exploitation should not be made public before the vulnerability has been resolved. Where public disclosure is necessary, a coordinated disclosure process between Kriko and the researcher is preferred.

Privacy and Data Protection

Personal, commercial or confidential information encountered during security research must be protected.

Access to such information must be kept to a minimum, and no data that is unnecessary for verifying the vulnerability should be retained, copied or disclosed. Personal or confidential information unintentionally obtained during testing should be securely deleted after the relevant vulnerability has been reported to Kriko.

Recognition and Rewards

Reporting a vulnerability does not create any entitlement to financial compensation or reward.

At its sole discretion, Kriko may acknowledge or recognize researchers who responsibly report significant security vulnerabilities. Such recognition does not mean that Kriko operates a bug bounty program and does not create any obligation to provide compensation for future reports.

Contact

Security vulnerabilities and questions regarding this policy may be submitted to:

security@kriko.io

Track the digital heartbeat with Kriko

Subscribe to receive curated insights, news, and ideas shaping the digital landscape.