Scope: This document applies only to app.keydir.in and its related services.
SECTION_01 Scope
This policy covers security vulnerabilities in the KeyDir Application and its documentation site. The community directory at keydir.in is a separate service; if you find a vulnerability there, please follow the same process and it will be routed correctly.
SECTION_02 How to Report
- Email officialkeydir.in@gmail.com with subject
[SECURITY]. - Describe the vulnerability: what, where, steps to reproduce, and impact.
- Include only what is needed to demonstrate the issue.
- Give us at least 30 days to fix it before any public disclosure.
SECTION_03 What We Promise
- Acknowledgement — we confirm receipt within a few days.
- Investigation — we review and respond on validity and impact.
- A fix — valid issues are addressed and you are credited if you want.
- Good faith — good-faith reports made under this policy will not result in legal action against you.
SECTION_04 Safe Testing Rules
- Test only against your own accounts and data.
- Do not access or exfiltrate data beyond what is needed to demonstrate the issue.
- Do not disrupt the service for other users.
- Do not destroy or modify data.
- Coordinate any large-scale or unusual testing with us first.
Testing that violates these rules may be treated as unauthorized activity under the Acceptable Use Policy.
SECTION_05 Out of Scope
- Phishing and social-engineering of users.
- Denial-of-service attacks against the service.
- Attacks on third-party services the platform uses.
- Issues already fixed or reported, and non-security bugs (use the Contact page).
SECTION_06 Credit
We do not offer a bug bounty. We offer our thanks, credit on the platform where we maintain it, and a direct line to follow up on the fix. See also the Security page.