Skip to content

Security reporting

Katafract does not currently operate a public bug bounty or authorize public security testing.

  • No reward is offered or promised for unsolicited reports.
  • Do not scan, create test accounts, probe APIs, provision services, or attempt to access data without prior written authorization.
  • The prior public bug-bounty program was suspended on August 17, 2026. Reports received before that suspension remain under review and will be handled directly on their existing email threads.

If you accidentally discover a security issue through ordinary use, you may still email security@katafract.com. Please include a description, the affected product or URL, and only the evidence you already possess. Do not take additional steps to prove impact.

This policy may be replaced by a separately budgeted and explicitly scoped program with new terms and an explicit effective date.