We take security seriously. Report vulnerabilities responsibly and help us keep our users safe.
We aim to respond within:
24-48 hoursmooncloak operates a responsible disclosure program for security researchers, users, and the community to report potential security vulnerabilities in KodeTools products and services. We appreciate your efforts to responsibly disclose your findings.
Document the vulnerability with as much detail as possible:
Email your findings to [email protected]
We will acknowledge your report within 24-48 hours:
Once the vulnerability is fixed:
When conducting vulnerability research according to these guidelines, we consider this research to be:
We will not pursue legal action against researchers who discover and report vulnerabilities in accordance with this policy. We consider good-faith security research to be in the best interest of our users and the security community.
We're working on establishing a formal bug bounty program to reward security researchers who help us identify and fix vulnerabilities. This program will offer monetary rewards based on the severity and impact of reported vulnerabilities.
In the meantime: We deeply appreciate all responsible disclosures and will publicly acknowledge researchers (with permission) in our security advisories and hall of fame.
Want to be notified when we launch?
Notify MeWe follow secure coding practices and conduct regular code reviews to identify and fix vulnerabilities early.
We conduct security audits and penetration testing to identify and address potential vulnerabilities.
All data in transit is encrypted using TLS 1.3. Sensitive data at rest is encrypted using industry-standard algorithms.
We collect minimal data and follow privacy-first principles. No tracking, no analytics without consent.
We release security patches promptly and maintain our dependencies up-to-date to address known vulnerabilities.
Our team receives regular security training to stay informed about the latest threats and best practices.
We'd like to thank the following security researchers for responsibly disclosing vulnerabilities:
Be the first to be recognized! Report a vulnerability to get listed here.
Researchers are listed with their permission. If you prefer to remain anonymous, please let us know.
For sensitive security reports, you can encrypt your email using our PGP public key. This ensures that only mooncloak security team can read your report.
PGP key will be available soon. In the meantime, please send unencrypted reports to [email protected] or use the contact form for non-sensitive information.