Security
Responsible disclosure
KURAL welcomes good-faith security research. This policy is a public commitment that we will not pursue legal action against researchers who follow the rules below, and the SLAs we hold ourselves to when you report something.
Scope
kural.tech, app.kural.tech, api.kural.tech, status.kural.tech- Public-facing KURAL APIs documented at kural.tech/legal/ingestion
- The KURAL evidence-ledger cryptographic primitives
Out of scope
- Operator-tenant data — never test against a real operator's tenant
- Third-party subprocessors (report to them directly)
- Social engineering of KURAL staff
- DoS / volumetric attacks
- Physical attacks against KURAL infrastructure
Our commitments
- Acknowledgement within 2 business days
- Triage and severity assignment within 5 business days
- Critical-severity fix within 14 days (most are faster)
- Safe-harbour: we will not pursue legal action for good-faith research that follows this policy
- Public credit (with your permission) in the security changelog
How to report
Email security@kural.tech with a clear write-up and any proof-of-concept. PGP key available on request.