Security
Vulnerability disclosure policy
How to report security vulnerabilities in KeyValt responsibly.
Last updated: 4 October 2026
Keeping your vault safe is our highest priority. If you believe you have found a security vulnerability in KeyValt — the web app, API, or browser extension — please let us know at security@keyvalt.com. A machine-readable contact is also published at /.well-known/security.txt.
Please include
- A description of the issue and its impact
- Steps to reproduce, proof-of-concept code, or screenshots
- Affected URLs, extension version and browser
- How you would like to be credited, if at all
Our commitment
- We will acknowledge your report within 3 business days and keep you informed of progress.
- We will not pursue legal action against good-faith research that follows this policy.
- We will credit you (with permission) once the issue is fixed.
Rules of engagement
- Only test against accounts you own. Never access, modify or delete other users’ data.
- Do not perform denial-of-service, spam, social engineering or physical attacks.
- Do not test against third-party portals (government, banking or other sites) — they are out of scope and governed by their own policies.
- Give us reasonable time to remediate before public disclosure.
In scope
- Cryptographic weaknesses in vault encryption, key derivation or sharing
- Autofill on the wrong origin, domain-verification bypasses and portal-config signature bypasses
- Authentication, session, authorization (IDOR) and CSRF issues
- Extension message-passing and permission issues
- Payment and webhook manipulation