Title: Vulnerability Disclosure Policy
Author: Kriko
Published: Aug 8, 2026
Last modified: Aug 13, 2026

---

 1.  [Home](https://kriko.io/) /
 2.  [Company Policies](https://kriko.io/company-policies) /
 3.  [Information Technology and Data Management Policies](https://kriko.io/company-policies/information-technology-and-data-management-policies)/
 4.  Vulnerability Disclosure Policy

# Company Policies

The principles that guide every team at Kriko. From how we hire and protect data
to how we uphold quality and sustainability.

## Vulnerability Disclosure Policy

## Purpose

This policy sets out the principles for the responsible and secure reporting of 
vulnerabilities identified in systems owned or managed by Kriko. Kriko recognizes
the contribution that independent security researchers can make to identifying vulnerabilities
before they are exploited and supports good-faith security research.

### Scope

This policy applies to the following Kriko digital assets:

 * kriko.io and subdomains managed by Kriko.
 * Publicly accessible web applications and tools operated by Kriko.
 * APIs and other internet-facing services operated by Kriko.
 * Other digital systems explicitly identified by Kriko as being within the scope
   of this policy.

Third-party platforms, customer systems, customer advertising accounts, external
SaaS services and other third-party infrastructure that Kriko does not own or control
are outside the scope of this policy.

If there is any uncertainty as to whether a system is within scope, Kriko should
be contacted before any testing is conducted.

### Reporting a Vulnerability

Identified vulnerabilities should be reported to:

security@kriko.io

Reports should include, where possible, the following information:

 * The affected URL, application, system or service.
 * A description of the vulnerability and its potential impact.
 * The steps required to reproduce the vulnerability.
 * Screenshots, request and response examples, proof-of-concept information, where
   available.
 * Any other technical information that may assist in evaluating the issue.

Reports should not include personal data, user information, passwords, customer 
data or other confidential information that is not necessary to assess the vulnerability.

### Responsible Security Research

Security research must be conducted in good faith and solely for the purpose of 
identifying and reporting vulnerabilities.

 * Activities that may adversely affect the availability or performance of Kriko
   systems must be avoided.
 * Only the minimum level of testing required to demonstrate the vulnerability should
   be performed.
 * Testing must stop immediately if personal data, customer information, credentials
   or other confidential information is accessed.
 * Data accessed during testing must not be modified, deleted, downloaded, disclosed
   or used for any other purpose.
 * Once sufficient evidence has been obtained to demonstrate the existence of the
   vulnerability, no attempt should be made to gain additional access.

### Prohibited Activities

This policy does not authorize the following activities:

 * Denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks.
 * High-volume automated requests that may affect system performance or availability.
 * Credential stuffing, password spraying or large-scale brute-force attacks.
 * Social engineering, phishing, impersonation or physical security testing.
 * Targeting Kriko employees, customers, business partners or other third parties.
 * Use of malware, ransomware, backdoors or persistent access mechanisms.
 * Accessing, downloading, modifying or deleting more data than is necessary to 
   demonstrate a vulnerability.
 * Testing third-party systems that Kriko does not own or control.
 * Public disclosure of an identified vulnerability without giving Kriko a reasonable
   period of time to remediate the issue.

### Good-Faith Research and Authorization

Kriko supports good-faith security research conducted in accordance with this policy.

Researchers are expected to limit their testing to systems within the scope of this
policy, avoid unnecessary harm, perform only the actions required to verify the 
vulnerability and report identified vulnerabilities responsibly.

To the extent permitted by applicable law, Kriko does not intend to initiate legal
proceedings against researchers solely for security research conducted in good faith
and in accordance with this policy.

This approach does not apply to activities that violate applicable laws, affect 
third-party systems or exceed the scope of this policy.

### Evaluation of Reports

Kriko evaluates received vulnerability reports to determine their validity, severity
and potential impact.

 * Additional technical information or reproduction steps may be requested from 
   the researcher where necessary.
 * Confirmed vulnerabilities are prioritized according to their severity, exploitability
   and potential impact.
 * Appropriate corrective and preventive security measures are implemented.
 * Remediation timelines may vary depending on the technical complexity and operational
   impact of the issue.

### Coordinated Disclosure

Researchers should provide Kriko with a reasonable period of time to investigate
and remediate identified vulnerabilities before publicly disclosing them.

Technical information that could facilitate exploitation should not be made public
before the vulnerability has been resolved. Where public disclosure is necessary,
a coordinated disclosure process between Kriko and the researcher is preferred.

### Privacy and Data Protection

Personal, commercial or confidential information encountered during security research
must be protected.

Access to such information must be kept to a minimum, and no data that is unnecessary
for verifying the vulnerability should be retained, copied or disclosed. Personal
or confidential information unintentionally obtained during testing should be securely
deleted after the relevant vulnerability has been reported to Kriko.

### Recognition and Rewards

Reporting a vulnerability does not create any entitlement to financial compensation
or reward.

At its sole discretion, Kriko may acknowledge or recognize researchers who responsibly
report significant security vulnerabilities. Such recognition does not mean that
Kriko operates a bug bounty program and does not create any obligation to provide
compensation for future reports.

### Contact

Security vulnerabilities and questions regarding this policy may be submitted to:

security@kriko.io

##  Communication Policies

 *  [Internal Communication and Collaboration Policy](https://kriko.io/company-policies/communication-policies/internal-communication-and-collaboration-policy)
 *  [Internal Communication Channels and Meeting Policy](https://kriko.io/company-policies/communication-policies/internal-communication-channels-and-meeting-policy)
 *  [Social Media Policy](https://kriko.io/company-policies/communication-policies/social-media-policy)

##  Crisis and Incident Management Policies

 *  [Crisis Communication and Reputation Management Policy](https://kriko.io/company-policies/crisis-and-incident-management-policies/crisis-communication-and-reputation-management-policy)
 *  [Emergency Planning and Response Policy](https://kriko.io/company-policies/crisis-and-incident-management-policies/emergency-planning-and-response-policy)

##  Disciplinary Policies

 *  [Disciplinary Policy](https://kriko.io/company-policies/disciplinary-policies/disciplinary-policy)

##  Human Resources Policies

 *  [Diversity, Equity and Inclusion Policy](https://kriko.io/company-policies/human-resources-policies/recruitment-policy)
 *  [Employee Training and Development Policy](https://kriko.io/company-policies/human-resources-policies/termination-policy)
 *  [Anti-Discrimination and Diversity Policy](https://kriko.io/company-policies/human-resources-policies/anti-discrimination-and-diversity-policy)
 *  [Occupational Health and Safety Policy](https://kriko.io/company-policies/human-resources-policies/remote-hybrid-work)
 *  [Recruitment and Termination Policy](https://kriko.io/company-policies/human-resources-policies/recruitment-and-termination-policy)
 *  [Working Hours, Leave and Absence Policy](https://kriko.io/company-policies/human-resources-policies/working-hours-leave-and-absence-policy)

##  Business Ethics and Compliance Policies

 *  [Password Creation and Use Policy](https://kriko.io/company-policies/business-ethics-and-compliance-policies/data-protection-policy)
 *  [Transparency and Reporting Policy](https://kriko.io/company-policies/business-ethics-and-compliance-policies/acceptable-use-policy)
 *  [Conflict of Interest and Anti-Bribery Policy](https://kriko.io/company-policies/business-ethics-and-compliance-policies/conflict-of-interest-and-anti-bribery-policy)
 *  [Data Privacy and Security Policy](https://kriko.io/company-policies/business-ethics-and-compliance-policies/data-privacy-and-security-policy)
 *  [Ethical Conduct and Integrity Policy](https://kriko.io/company-policies/business-ethics-and-compliance-policies/ethical-conduct-and-integrity-policy)
 *  [Legal and Regulatory Compliance Policy](https://kriko.io/company-policies/business-ethics-and-compliance-policies/incident-response)

##  Customer Relations Policies

 *  [Customer Data Privacy and Security Policy](https://kriko.io/company-policies/quality-compliance/quality-management)
 *  [Complaint Management and Feedback Policy](https://kriko.io/company-policies/quality-compliance/anti-bribery-corruption)
 *  [Customer Satisfaction Policy](https://kriko.io/company-policies/quality-compliance/code-of-conduct)

##  Information Technology and Data Management Policies

 *  [Ransomware, Phishing Attacks, Email and Internet Use Policy](https://kriko.io/company-policies/information-technology-and-data-management-policies/environmental-policy)
 *  [Vulnerability Disclosure Policy](https://kriko.io/company-policies/information-technology-and-data-management-policies/vulnerability-disclosure-policy)
 *  [Software Licensing and Usage Policy](https://kriko.io/company-policies/information-technology-and-data-management-policies/social-responsibility)
 *  [Data Backup and Recovery Policy](https://kriko.io/company-policies/information-technology-and-data-management-policies/supplier-code-of-conduct)
 *  [Data Security and Protection Policy](https://kriko.io/company-policies/information-technology-and-data-management-policies/data-security-and-protection-policy)
 *  [Information Technology Use and Access Policy](https://kriko.io/company-policies/information-technology-and-data-management-policies/information-technology-use-and-access-policy)

## Track the digital heartbeat  with Kriko

Subscribe to receive curated insights, news, and ideas shaping the digital landscape.

  By checking this box, you acknowledge and accept our [privacy policy](https://kriko.io/privacy-policy).