generated: '2026-07-25' method: searched probe: true source: https://kalepa.com/security policy: - https://kalepa.com/security contact: - security@kalepa.com program: type: responsible-disclosure bug_bounty: false paid_rewards: false platform: none safe_harbor: >- "we will not take legal action against you nor ask law enforcement to investigate you provided you comply with the following Responsible Disclosure Guidelines" security_txt: false scope: domains: - kalepa.com - kalepainsurance.com - kalepa.co - kalepa.io note: '"and any subdomain" — verbatim from the policy page.' eligible_bug_classes: - Cross-site Scripting - Open redirect - Cross-site request forgery - File inclusion - Authentication bypass - Server-side code execution ineligible_bug_classes: - Missing cookie flags on non-session or third-party cookies - Logout CSRF - Social engineering - Denial of service - SSL BEAST/CRIME and similar - Email spoofing, SPF, DMARC and DKIM issues guidelines: - Provide reproduction detail and a proof of concept. - Make a good-faith effort to avoid privacy violations, data destruction and service degradation. - Do not modify or access data that does not belong to you. - Give Kalepa reasonable time to correct the issue before publishing. - Do not perform research that could impact other users. report_format: fields: [Name, Twitter, Bug type, Domain, Severity, URL, PoC, CVSS (optional), CWSS (optional)] evidence: - source: https://kalepa.com/security kind: disclosure page status: 200 keywords: - vulnerability - responsible disclosure - security research - report a security - security issue - security@ - source: well-known/kalepa-well-known.yml kind: security.txt status: 404 note: No RFC 9116 security.txt published at kalepa.com or api.kalepa.com.