A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# security.txt for Kiva Logic Contact: mailto:security@kivalogic.com Expires: 2026-04-07T00:00:00Z Preferred-Languages: en Canonical: https://www.kivalogic.com/.well-known/security.txt Policy: We welcome responsible disclosure of security vulnerabilities. Please follow the guidelines below. Scope: Only our production systems under *.kivalogic.com are in scope. Do not target test servers, staging environments, third-party platforms, or vendors. Legal: We will not pursue legal action against security researchers who: - Act in good faith - Do not exploit or abuse vulnerabilities - Avoid accessing, modifying, or deleting data Unauthorized access or data extraction is still illegal. Proceed at your own risk. No SLA: We do not guarantee a response or acknowledgment. Reports are prioritized at our discretion. No Duplicates: We do not respond to duplicate, previously reported, or known issues. Submission Guidelines: To have your report considered, include: - Clear and concise description - Steps to reproduce - Working proof-of-concept - Real-world impact and affected systems Thanks for helping us keep Kiva Logic secure.
This policy crawled by Onyphe on the 2026-03-02 is sorted as securitytxt.
FireBounty © 2015-2026