Report a security problem
Found a vulnerability in Private.Ki? Where to write, what to include, how to encrypt the report, and what our coordinated disclosure policy promises you.
This page is for vulnerabilities — a flaw in Private.Ki itself that someone could exploit. If an account is sending spam, phishing or threats, that is abuse, not a vulnerability: see Report abuse or spam instead.
Where to write
Email [email protected] with "Security report" in the subject. A person reads it.
Encrypted reports are welcome and preferred. Our public key is published at private.ki/pgp/[email protected], and the contact page shows the same key with its fingerprint so you can compare the two first. If you have no PGP setup, send it unencrypted rather than not at all.
What to include
- What you found, in a sentence or two.
- Where — the host, URL, app screen or endpoint.
- How to reproduce it, step by step, from a clean start.
- A proof of concept we can run ourselves.
- What an attacker could do with it.
Use your own test accounts, and stop as soon as you have shown the problem exists.
What happens next
We acknowledge within 72 hours and send a substantive update within 7 days. We aim to fix critical issues within 30 days, and we say so plainly when something will take longer.
Good-faith research inside the published scope has safe harbour: we will not take legal action over it and will not refer it to law enforcement. We do not run a paid bug bounty — we may offer a reward at our discretion for a high-impact report, and we credit researchers who want to be named.
The full terms, the scope, and the list of things we do not accept are on the website: Reporting a security problem. The same contact details are published in machine-readable form at private.ki/.well-known/security.txt.