Security

Reporting a vulnerability

Kordio decides what is allowed to happen to money before it happens. If you have found a way around that, we want to hear about it directly.

Last updated: 31 August 2026

1. How to report

Email security@kordio.io with enough detail for us to reproduce the issue: the endpoint or screen, the steps you took, and what you saw that you should not have. A short proof of concept is worth more than a scanner export.

Tell us if you believe the issue is being exploited already, and we will treat it as an incident rather than a report.

2. What we commit to

  • We acknowledge every report within three working days.
  • We tell you our assessment, including when we decide something is not a vulnerability and why.
  • We will not pursue legal action, and will not ask your internet provider or employer to act against you, for research carried out in good faith under this policy.
  • We credit reporters who want to be named, once a fix is released.

Kordio does not currently run a paid bounty programme. We will say so plainly rather than imply otherwise.

3. In scope

  • app.kordio.io, the Kordio console.
  • api.kordio.io, the Control and Ledger APIs.
  • kordio.io and docs.kordio.io.

4. Out of scope

These are not accepted, because they either describe a risk we have already accepted or they harm the service and its customers:

  • Denial of service, load testing, and anything that degrades the service for other people.
  • Social engineering of our team, our customers, or our vendors, and physical attacks.
  • Reports produced only by an automated scanner, with no demonstrated impact.
  • Missing headers, cookie flags, or TLS configuration with no exploitable consequence.
  • Findings in third party services we do not operate. Report those to the vendor.

5. Rules for testing

  • Use your own account and your own workspace. Sign up for a second one if you need two.
  • Stop as soon as you have confirmed a vulnerability. Do not read, copy, alter, or keep data belonging to anyone else.
  • If you access someone else's data by accident, stop, tell us what you saw, and delete your copy.
  • Give us a reasonable period to fix the issue before you publish. Ninety days is our default, and we will agree something shorter with you if the fix lands sooner.

Testing that stays inside these rules is authorised. Testing that leaves them is not covered by this policy.

6. Contact

Reports and questions about this policy both go to security@kordio.io. The machine readable version of this page is at /.well-known/security.txt.