generated: '2026-07-27' method: searched probe: true source: https://www.kraken.tech/vulnerability-disclosure-process url: https://www.kraken.tech/vulnerability-disclosure-process summary: >- Kraken Technologies runs a published Vulnerability Disclosure Process, explicitly separate from a private HackerOne program. Reports go through a submission form, not an email address; there is no bounty. Kraken commits to a 2-business-day first response and 2-business-day triage target. The automated probe missed this page because it sits at a non-standard path (/vulnerability-disclosure-process, not /security or /responsible-disclosure) and because kraken.tech serves no /.well-known/security.txt. policy: - https://www.kraken.tech/vulnerability-disclosure-process contact: - type: form value: 'Submission Form linked from https://www.kraken.tech/vulnerability-disclosure-process ("Report a vulnerability")' bounty: offered: false verbatim: 'Please note we do not offer monetary rewards for vulnerability disclosures.' private_program: platform: HackerOne public: false verbatim: 'Our Vulnerability Disclosure process is separate to our Private HackerOne program.' response_targets: first_response: 2 business days triage: 2 business days verbatim: >- "Kraken will make a best effort to meet the following response time targets for vulnerability report submissions: Time to first response (from reporting) = 2 business days; Time to triage (from reporting) = 2 business days." scope: in_scope: - Security vulnerabilities identified in any internet-facing service owned, operated, or controlled by Kraken. out_of_scope: - Rate limiting issues on Kraken's demo form - Clickjacking on pages with no sensitive actions - Unauthenticated/logout/login CSRF - Attacks requiring MITM or physical access to a user's device - Previously known vulnerable libraries without a working proof of concept - CSV injection without demonstrating a vulnerability - Missing best practices in SSL/TLS configuration - Any activity that could lead to disruption of service (DoS) - Content spoofing and text injection without an attack vector or HTML/CSS modification rules: - Provide detailed reports with reproducible steps. - Submit one vulnerability per report, unless chaining is needed to show impact. - Social engineering (phishing, vishing, smishing) is prohibited. - Make a good-faith effort to avoid privacy violations, data destruction, and service interruption; only interact with accounts you own or have explicit permission for. security_txt: present: false probes: - {url: 'https://www.kraken.tech/.well-known/security.txt', status: 404} - {url: 'https://kraken.tech/.well-known/security.txt', status: 404} - {url: 'https://docs.kraken.tech/.well-known/security.txt', status: 200, note: 'SSO login page (text/html), not RFC 9116'} gap: >- Kraken has a real disclosure process but no RFC 9116 security.txt pointing at it — a one-line fix that would make the policy machine-discoverable. related_contacts: data_protection_officer: dpo@kraken.tech privacy: privacy@kraken.tech evidence: - {source: 'https://www.kraken.tech/vulnerability-disclosure-process', kind: disclosure-policy, status: 200, date: '2026-07-27'} - {source: 'https://www.kraken.tech/legal/trust-center', kind: security-program, status: 200, date: '2026-07-27'}