Responsible disclosure
How to report a security vulnerability in Kula Intelligence.
Last updated
Was this helpful?
How to report a security vulnerability in Kula Intelligence.
We take the security of studios' data seriously and welcome good-faith reports from security researchers and users.
Email security@kula.digital with:
A description of the issue and where you found it.
Steps to reproduce (proof-of-concept, requests, screenshots).
The potential impact as you see it.
If you need to share sensitive details, ask in your first message and we'll arrange an encrypted channel.
We aim to acknowledge your report within a few business days.
We'll keep you updated on our assessment and the fix.
With your permission, we're happy to credit you once the issue is resolved.
Please help us keep studios' data safe while you research:
Only test against your own account or data, or a test account we provide. Never access, modify, or exfiltrate another studio's data.
Don't run denial-of-service tests, spam, or social-engineering against our staff or users.
Give us reasonable time to fix an issue before disclosing it publicly.
We will not pursue or support legal action against researchers who act in good faith and follow these guidelines.
Reports that are typically not actionable on their own: missing security headers without a demonstrated impact, rate-limiting on non-sensitive endpoints, and findings that require a compromised device or a already-privileged account. When in doubt, send it anyway — we'd rather hear about it.
Kula Intelligence is read-mostly and tightly scoped by design — it moves no money and writes nothing back to your connected tools (see Security & data handling). If you believe a tool behaves outside those bounds, that's exactly the kind of report we want.
Last updated
Was this helpful?
Was this helpful?