Reporting a security vulnerability
If you believe you have found a security vulnerability in a Kris product or service, email:
security@krisatwork.comPlease include:
- A description of the vulnerability and its potential impact
- The affected product, service, URL, or version
- Steps required to reproduce the issue
- Relevant screenshots, logs, or proof-of-concept material
- Your preferred contact information
Do not include personal data, customer data, credentials, or other sensitive information unless Kris requests it through an appropriate secure channel.
Scope
This policy covers:
- Software developed and distributed by Kris
- Internet-facing services operated by Kris
- Kris-owned domains and APIs
Customer-managed infrastructure and third-party services are outside our control. Vulnerabilities in Kris software deployed within customer-managed infrastructure may still be reported to us.
Responsible testing
When investigating a potential vulnerability:
- Access only accounts and data that you own or are authorized to use
- Do not access, modify, download, retain, or disclose another person's data
- Do not disrupt services or degrade their availability
- Do not perform denial-of-service testing, social engineering, phishing, spam, or physical attacks
- Do not use high-volume automated scanning
- Stop testing and contact us immediately if you encounter customer data or sensitive information
What happens after reporting
Kris will review submitted reports and prioritize remediation based on the severity, impact, and exploitability of the issue.
We ask researchers to allow reasonable time for investigation and remediation before publicly disclosing a vulnerability, and to coordinate any disclosure with us.
Safe harbour
Kris will not pursue legal action against researchers for good-faith security research performed in accordance with this policy.
This protection does not apply to actions that harm users, access or retain data without authorization, disrupt services, or violate the requirements above.
Rewards
Kris does not currently operate a public bug-bounty programme. Submission of a report does not create an entitlement to payment or other compensation.
Policy changes
Kris may update this policy periodically.
Last updated: September 2026