Last updated: July 28, 2026
KaryaFlow™ takes the security of its products and the privacy of its users seriously. We welcome reports from security researchers and members of the public about potential vulnerabilities in our systems. We commit to acknowledging reports promptly, investigating in good faith, and keeping reporters informed of progress.
The following assets are in scope for this program:
The following are out of scope:
Send your report to our security team at the address below. Please include enough detail for us to reproduce and triage the issue:security@karyaflowhq.com.
We commit to the following response times for valid reports:
When you conduct security research in good faith and in accordance with this policy, we will not pursue legal action against you for the research itself. We consider the research authorized under the Computer Fraud and Abuse Act, the Indian Information Technology Act, and analogous laws in other jurisdictions, and we will not refer the matter to law enforcement. We ask that you: (a) avoid privacy violations, destruction of data, and interruption or degradation of our service; (b) only interact with accounts you own or have explicit permission to access; and (c) do not exploit a vulnerability beyond what is necessary to demonstrate it.
We are developing a public recognition page for researchers who help us improve KaryaFlow™ security. Researchers who report valid, in-scope vulnerabilities will be listed (with their consent) once the program is fully operational.