For the complete documentation index, see llms.txt. This page is also available as Markdown.

Responsible disclosure

How to report a security vulnerability in Kula Intelligence.

We take the security of studios' data seriously and welcome good-faith reports from security researchers and users.

How to report

Email security@kula.digital with:

  • A description of the issue and where you found it.

  • Steps to reproduce (proof-of-concept, requests, screenshots).

  • The potential impact as you see it.

If you need to share sensitive details, ask in your first message and we'll arrange an encrypted channel.

What to expect

  • We aim to acknowledge your report within a few business days.

  • We'll keep you updated on our assessment and the fix.

  • With your permission, we're happy to credit you once the issue is resolved.

Good-faith guidelines

Please help us keep studios' data safe while you research:

  • Only test against your own account or data, or a test account we provide. Never access, modify, or exfiltrate another studio's data.

  • Don't run denial-of-service tests, spam, or social-engineering against our staff or users.

  • Give us reasonable time to fix an issue before disclosing it publicly.

We will not pursue or support legal action against researchers who act in good faith and follow these guidelines.

Out of scope

Reports that are typically not actionable on their own: missing security headers without a demonstrated impact, rate-limiting on non-sensitive endpoints, and findings that require a compromised device or a already-privileged account. When in doubt, send it anyway — we'd rather hear about it.

A note for connected AI clients

Kula Intelligence is read-mostly and tightly scoped by design — it moves no money and writes nothing back to your connected tools (see Security & data handling). If you believe a tool behaves outside those bounds, that's exactly the kind of report we want.

Last updated

Was this helpful?