Reporting a vulnerability
Found a security issue in Kryex Code, Kryex Server, Kryex Admin, or this website? Tell us directly, before posting it publicly — we'll work with you to fix it.
How to report
Email deepak@kryexlabs.com with a description of the issue, the component it affects, and steps to reproduce it. Include a proof of concept if you have one — it's the fastest way for us to confirm and fix the problem. If the report involves sensitive details, ask us for a way to share it privately before sending anything over email.
What to expect
We acknowledge every report within 2 business days and give you an initial assessment — confirmed, not reproducible, or under investigation — within 5 business days. For a confirmed issue, we'll keep you updated as we work on a fix and tell you when it ships.
Scope
This covers the Kryex Code desktop app, Kryex Server, Kryex Admin, and kryexlabs.com. Please don't test against another customer's deployment or data without their separate permission — test against your own instance, or ask us for a sandbox.
Good-faith research
We won't pursue legal action against reports made in good faith that follow this process: no public disclosure before a fix ships, no access to data beyond what's needed to demonstrate the issue, and no disruption to other users or systems.
Credit
If you'd like to be credited once the issue is fixed, let us know in your report and we'll acknowledge you — otherwise we keep reports confidential by default.