Security · SEC·01
Security.
How Kitalon Labs patches, monitors, and protects this site, and how to report a vulnerability.
Last reviewed: August 9, 2026
How to report a vulnerability
Report security issues privately by email to [email protected]. Include the affected URL, a minimal reproduction, and the impact you observed. Reports are acknowledged, investigated, and answered. No bug bounty is offered, and automated scanners that generate large request volumes are not welcome.
Patch cadence
Severity is assessed against the affected component and the CVSS score from the vendor or the dependency scanner.
| Severity | Response | Patched within |
|---|---|---|
| Critical | Immediate. Stop other work, patch, deploy, verify. | 24 hours |
| High | Next working day at the latest. | 72 hours |
| Moderate | Next weekly window. | 7 days |
| Low | Next monthly review. | 30 days |
Dependency monitoring
- Dependabot opens grouped pull requests weekly and security alerts immediately. Both are reviewed before merge.
- A full dependency audit (npm audit) runs monthly. The last audit before this page was written reported zero known vulnerabilities.
- The framework is kept on the current patched minor line, so new framework advisories are picked up by routine upgrades rather than emergency migration.
What this site collects
This site has no forms, no accounts, no cookies, and no analytics scripts. The hosting provider and the site keep technical request logs (path, user agent, referrer) for operations. The site uses the referrer field only to count visits that arrive from AI chat surfaces. No personal data is intentionally collected, sold, or shared.
The Android apps published by Kitalon Labs are separate products and are covered by their own documents: Privacy Policy and Terms of Service.
Contact
Security contact: [email protected]
Machine-readable policy: security.txt
