KaryaFlow

Responsible Disclosure

Last updated: July 28, 2026

1. Our commitment

KaryaFlow™ takes the security of its products and the privacy of its users seriously. We welcome reports from security researchers and members of the public about potential vulnerabilities in our systems. We commit to acknowledging reports promptly, investigating in good faith, and keeping reporters informed of progress.

2. Scope

The following assets are in scope for this program:

  • karyaflowhq.com and its subdomains.
  • The KaryaFlow™ web application (after authentication).
  • Official KaryaFlow™ mobile and desktop clients.
  • Our public APIs (documentation available on request).

3. Out of scope

The following are out of scope:

  • Third-party services we link to or embed (please report directly to the vendor).
  • Vulnerabilities requiring physical access to a user's device.
  • Self-XSS, clickjacking without a demonstrated impact, or missing security headers with no exploit path.
  • Rate-limiting issues that do not lead to a clear security impact.
  • Reports generated entirely by automated scanners without manual verification.

4. How to report

Send your report to our security team at the address below. Please include enough detail for us to reproduce and triage the issue:security@karyaflowhq.com.

  • A clear summary of the vulnerability and the asset affected.
  • Step-by-step reproduction instructions.
  • The potential impact and a suggested severity if known.
  • Any proof-of-concept code, screenshots, or screen recordings that help us understand the issue.

5. Our response

We commit to the following response times for valid reports:

  • Acknowledgement within 3 business days.
  • Initial triage and severity assessment within 10 business days.
  • Status updates at least every 14 calendar days until resolution.
  • Coordinated disclosure: we ask that you give us a reasonable window (typically 90 days from acknowledgement) to address the issue before any public disclosure.

6. Safe harbor

When you conduct security research in good faith and in accordance with this policy, we will not pursue legal action against you for the research itself. We consider the research authorized under the Computer Fraud and Abuse Act, the Indian Information Technology Act, and analogous laws in other jurisdictions, and we will not refer the matter to law enforcement. We ask that you: (a) avoid privacy violations, destruction of data, and interruption or degradation of our service; (b) only interact with accounts you own or have explicit permission to access; and (c) do not exploit a vulnerability beyond what is necessary to demonstrate it.

7. Recognition

We are developing a public recognition page for researchers who help us improve KaryaFlow™ security. Researchers who report valid, in-scope vulnerabilities will be listed (with their consent) once the program is fully operational.