RESPONSIBLE DISCLOSURE

Found a vulnerability in the KeyDir Application? Report it the right way and we will fix it, credit you, and not sue you.

Last updated 2026-08-01 Version v1.0
Scope: This document applies only to app.keydir.in and its related services.

SECTION_01 Scope

This policy covers security vulnerabilities in the KeyDir Application and its documentation site. The community directory at keydir.in is a separate service; if you find a vulnerability there, please follow the same process and it will be routed correctly.

SECTION_02 How to Report

  1. Email officialkeydir.in@gmail.com with subject [SECURITY].
  2. Describe the vulnerability: what, where, steps to reproduce, and impact.
  3. Include only what is needed to demonstrate the issue.
  4. Give us at least 30 days to fix it before any public disclosure.

SECTION_03 What We Promise

  • Acknowledgement — we confirm receipt within a few days.
  • Investigation — we review and respond on validity and impact.
  • A fix — valid issues are addressed and you are credited if you want.
  • Good faith — good-faith reports made under this policy will not result in legal action against you.

SECTION_04 Safe Testing Rules

  • Test only against your own accounts and data.
  • Do not access or exfiltrate data beyond what is needed to demonstrate the issue.
  • Do not disrupt the service for other users.
  • Do not destroy or modify data.
  • Coordinate any large-scale or unusual testing with us first.

Testing that violates these rules may be treated as unauthorized activity under the Acceptable Use Policy.

SECTION_05 Out of Scope

  • Phishing and social-engineering of users.
  • Denial-of-service attacks against the service.
  • Attacks on third-party services the platform uses.
  • Issues already fixed or reported, and non-security bugs (use the Contact page).

SECTION_06 Credit

We do not offer a bug bounty. We offer our thanks, credit on the platform where we maintain it, and a direct line to follow up on the fix. See also the Security page.