Introduction
Keldan values the contributions of security researchers, customers, and the broader security community in helping us maintain a secure platform.
If you believe you have identified a security vulnerability affecting our Services, we encourage you to report it responsibly.
This Responsible Disclosure Policy explains how to report vulnerabilities and how Keldan will work with security researchers during the disclosure process.
Our Commitment
We are committed to:
- treating all reports respectfully;
- investigating legitimate security reports;
- working collaboratively with researchers;
- resolving confirmed vulnerabilities according to risk and operational impact;
- improving the security of our Services through responsible disclosure.
We appreciate responsible and coordinated vulnerability reporting.
Scope
This Policy applies to vulnerabilities affecting Services operated by Keldan, including where applicable:
- websites;
- APIs;
- cloud services;
- administrative portals;
- SDKs;
- developer tools;
- authentication services;
- infrastructure under our operational control.
Third-party services are governed by the responsible disclosure programs of their respective providers.
How to Report a Vulnerability
Please submit vulnerability reports to:
security@keldan.com.br
Whenever possible, include:
- a description of the vulnerability;
- affected systems;
- reproduction steps;
- proof of concept (if available);
- estimated impact;
- screenshots or supporting evidence where appropriate.
Providing clear information helps us investigate more efficiently.
What We Ask From Researchers
We ask researchers to:
- act in good faith;
- avoid harming customers;
- avoid accessing unnecessary data;
- stop testing after confirming a vulnerability;
- keep vulnerabilities confidential until remediation;
- avoid service disruption;
- avoid privacy violations;
- avoid social engineering against our personnel;
- avoid physical attacks;
- comply with applicable laws.
Responsible disclosure benefits everyone.
Safe Harbor
Provided that your research is conducted in good faith and in accordance with this Policy, Keldan will not intentionally pursue legal action against security researchers solely for identifying and responsibly reporting security vulnerabilities.
This Safe Harbor does not apply to activities involving:
- unauthorized data exfiltration;
- destruction of information;
- denial-of-service attacks;
- extortion;
- malware deployment;
- physical intrusion;
- social engineering;
- unlawful access beyond what is reasonably necessary to verify a vulnerability.
Nothing in this Policy limits rights or obligations under applicable law.
Our Commitments
After receiving a report, we will make commercially reasonable efforts to:
- acknowledge receipt;
- assess the reported issue;
- communicate with the researcher when appropriate;
- prioritize remediation according to risk;
- notify the reporter when the issue has been resolved, where feasible.
Response times may vary depending on the complexity of the investigation.
What Is Out of Scope
The following generally fall outside this Policy:
- spam reports;
- social engineering;
- phishing simulations;
- physical security testing;
- denial-of-service attacks;
- automated vulnerability scans without prior authorization;
- vulnerabilities affecting unsupported software;
- vulnerabilities requiring unrealistic attack scenarios;
- issues involving third-party providers outside our operational control.
Disclosure Process
We encourage coordinated disclosure.
Researchers should allow Keldan a reasonable opportunity to investigate and remediate confirmed vulnerabilities before publicly disclosing technical details.
Where appropriate, Keldan may coordinate public disclosure with the reporting researcher.
Recognition
Keldan appreciates the efforts of responsible security researchers.
At this time, Keldan does not operate a public bug bounty program.
We may choose to acknowledge researchers who make significant contributions, subject to their consent.
Legal
This Policy does not create contractual rights or obligations.
Nothing in this Policy authorizes activities that violate applicable law or exceed the scope described herein.
Contact
Security Team
security@keldan.com.br
Website
https://www.keldan.com.br
Legal
legal@keldan.com.br

