Security reporting
No public testing program
Section titled “No public testing program”Katafract does not currently operate a public bug bounty or authorize public security testing.
- No reward is offered or promised for unsolicited reports.
- Do not scan, create test accounts, probe APIs, provision services, or attempt to access data without prior written authorization.
- The prior public bug-bounty program was suspended on August 17, 2026. Reports received before that suspension remain under review and will be handled directly on their existing email threads.
If you accidentally discover a security issue through ordinary use, you may still email security@katafract.com. Please include a description, the affected product or URL, and only the evidence you already possess. Do not take additional steps to prove impact.
This policy may be replaced by a separately budgeted and explicitly scoped program with new terms and an explicit effective date.