Skip to content

Security

Vulnerability disclosure policy

How to report security vulnerabilities in KeyValt responsibly.

Last updated: 4 October 2026

Keeping your vault safe is our highest priority. If you believe you have found a security vulnerability in KeyValt — the web app, API, or browser extension — please let us know at security@keyvalt.com. A machine-readable contact is also published at /.well-known/security.txt.

Please include

  • A description of the issue and its impact
  • Steps to reproduce, proof-of-concept code, or screenshots
  • Affected URLs, extension version and browser
  • How you would like to be credited, if at all

Our commitment

  • We will acknowledge your report within 3 business days and keep you informed of progress.
  • We will not pursue legal action against good-faith research that follows this policy.
  • We will credit you (with permission) once the issue is fixed.

Rules of engagement

  • Only test against accounts you own. Never access, modify or delete other users’ data.
  • Do not perform denial-of-service, spam, social engineering or physical attacks.
  • Do not test against third-party portals (government, banking or other sites) — they are out of scope and governed by their own policies.
  • Give us reasonable time to remediate before public disclosure.

In scope

  • Cryptographic weaknesses in vault encryption, key derivation or sharing
  • Autofill on the wrong origin, domain-verification bypasses and portal-config signature bypasses
  • Authentication, session, authorization (IDOR) and CSRF issues
  • Extension message-passing and permission issues
  • Payment and webhook manipulation