KartExchange
← Legal & Trust Center

Security & Responsible Disclosure

Report vulnerabilities privately and with minimal data.

Review draft. This document has not been adopted as binding terms and is not legal advice.

Controls and limits

The application uses authenticated server flows, role checks and database row-level policies. Privileged access is restricted to server-side code. These are specific controls, not a promise of complete security, certification or incident-free operation.

Reporting

Email support@kartexchange.com with Security report in the subject. Include affected URL, reproduction steps, impact and minimal evidence. Do not access others’ data, disrupt service, perform social engineering or publicly disclose sensitive findings. Do not email credentials or bulk personal data.

Program status

No bounty or legal safe harbor is promised. A security.txt contact is provided for reporting. Incident classification, provider notification, breach deadlines and communications require the operator’s response process and counsel where appropriate.

Items for counsel and operator review

Approve scope, response ownership, incident playbook and any future safe-harbor language.

Version history

2026-09-05Initial engineering draft for counsel review; not adopted. Permanent version