Kryptonote / Security

Security policy

Last updated 24 August 2026

Security at Kryptonote

People trust Kryptonote with personal notes, source files, and work they have created. Protecting that content from unauthorised access or changes is part of how we build the product.

This page explains what we do and how to report a possible vulnerability. No system is free from security risk.

Our approach

Your account

Kryptonote uses authenticated sessions to control access to your account. Sensitive actions are available only to authorised users.

Your workspace content

Kryptonote ties files, conversations, and generated work to the account and workspace they belong to.

Connected accounts

Credentials for connected services are encrypted on the server and kept outside agent virtual machines. Agents receive only the results needed for the task, not the provider access token.

Product changes

We consider security when adding or changing functionality. We also review Kryptonote's software dependencies and install relevant security updates.

Service updates

When an incident affects availability, we publish updates on the Kryptonote status page.

Reporting a vulnerability

If you find a possible security issue in Kryptonote, email security@kryptonote.com.

Include enough detail for us to reproduce the issue:

  • The affected page, endpoint, or part of the product
  • What happened and what you expected to happen
  • Reproduction steps or a minimal proof of concept
  • The potential impact
  • Your preferred contact details and disclosure timeline
Do not include sensitive user data. Redact credentials, private content, access tokens, and personal information.

Research guidelines

When investigating an issue:

  • Use accounts and workspaces that you own or have explicit permission to test
  • Stop testing if you encounter data that does not belong to you
  • Collect only the information needed to demonstrate the issue
  • Avoid degrading the service or affecting other people
  • Give us reasonable time to investigate before publishing details

Testing that is not permitted

  • Denial-of-service, load testing, or intentional resource exhaustion
  • Social engineering, phishing, or attacks against Kryptonote personnel or users
  • Physical attacks against infrastructure, offices, or devices
  • Automated scanning that creates disruptive traffic
  • Accessing, modifying, retaining, or sharing another person's data
  • Installing malware or establishing persistent access

What happens after a report

  1. We review the report and may ask questions.
  2. We confirm whether we can reproduce it and assess its severity and reach.
  3. We develop and test a fix.
  4. We coordinate with the reporter if we need to disclose the issue publicly.

Kryptonote does not currently promise monetary rewards. Any recognition or reward is at our discretion and must be agreed separately.

Good-faith research

We will not pursue legal action over an accidental, good-faith violation of this policy if the researcher reports the issue promptly, avoids harm, and follows applicable law. This does not authorise testing against third-party systems or data.