Security & Responsible Disclosure
Report vulnerabilities privately and with minimal data.
Review draft. This document has not been adopted as binding terms and is not legal advice.
Controls and limits
The application uses authenticated server flows, role checks and database row-level policies. Privileged access is restricted to server-side code. These are specific controls, not a promise of complete security, certification or incident-free operation.
Reporting
Email support@kartexchange.com with Security report in the subject. Include affected URL, reproduction steps, impact and minimal evidence. Do not access others’ data, disrupt service, perform social engineering or publicly disclose sensitive findings. Do not email credentials or bulk personal data.
Program status
No bounty or legal safe harbor is promised. A security.txt contact is provided for reporting. Incident classification, provider notification, breach deadlines and communications require the operator’s response process and counsel where appropriate.
Items for counsel and operator review
Approve scope, response ownership, incident playbook and any future safe-harbor language.
Version history
2026-09-05 — Initial engineering draft for counsel review; not adopted. Permanent version
