We brought Kris to SaaStr AI 2026. Here's a glimpse.Read more →Meet us at Pavilion GTM2026, NYC. Booth #34.Get tickets →Kris@Work raises $3M seed funding led by InfoEdge Ventures.Read more →Meet us at Pavilion GTM2026, NYC. Booth #34.Get tickets →InfoEdge Ventures-Backed Kris@Work Strengthens Founding Team.Read more →We brought Kris to SaaStr AI 2026. Here's a glimpse.Read more →Meet us at Pavilion GTM2026, NYC. Booth #34.Get tickets →Kris@Work raises $3M seed funding led by InfoEdge Ventures.Read more →Meet us at Pavilion GTM2026, NYC. Booth #34.Get tickets →InfoEdge Ventures-Backed Kris@Work Strengthens Founding Team.Read more →

Security

Reporting a security vulnerability

If you believe you have found a security vulnerability in a Kris product or service, email:

security@krisatwork.com

Please include:

  • A description of the vulnerability and its potential impact
  • The affected product, service, URL, or version
  • Steps required to reproduce the issue
  • Relevant screenshots, logs, or proof-of-concept material
  • Your preferred contact information

Do not include personal data, customer data, credentials, or other sensitive information unless Kris requests it through an appropriate secure channel.

Scope

This policy covers:

  • Software developed and distributed by Kris
  • Internet-facing services operated by Kris
  • Kris-owned domains and APIs

Customer-managed infrastructure and third-party services are outside our control. Vulnerabilities in Kris software deployed within customer-managed infrastructure may still be reported to us.

Responsible testing

When investigating a potential vulnerability:

  • Access only accounts and data that you own or are authorized to use
  • Do not access, modify, download, retain, or disclose another person's data
  • Do not disrupt services or degrade their availability
  • Do not perform denial-of-service testing, social engineering, phishing, spam, or physical attacks
  • Do not use high-volume automated scanning
  • Stop testing and contact us immediately if you encounter customer data or sensitive information

What happens after reporting

Kris will review submitted reports and prioritize remediation based on the severity, impact, and exploitability of the issue.

We ask researchers to allow reasonable time for investigation and remediation before publicly disclosing a vulnerability, and to coordinate any disclosure with us.

Safe harbour

Kris will not pursue legal action against researchers for good-faith security research performed in accordance with this policy.

This protection does not apply to actions that harm users, access or retain data without authorization, disrupt services, or violate the requirements above.

Rewards

Kris does not currently operate a public bug-bounty programme. Submission of a report does not create an entitlement to payment or other compensation.

Policy changes

Kris may update this policy periodically.

Last updated: September 2026