Reporting problems

Policy



We're pretty simple when it comes to coordinated vulnerability disclosures.

  • Security issues with our site or infrastructure can be reported to security@kedalion.nl. (S/MIME key)
  • We do not have a bug bounty program, nor do we offer monetary in any way; this is simply not in our budget.
  • If someone reports a critically destructive vulnerability in our infrastructure, then we will try to compensate them in some way.
  • We will acknowledge anyone who reports issues, here on this page.
  • Spam issues may be reported to abuse@kedalion.nl.
  • And yes, we have a security.txt.

The public key for S/MIME email to security@kedalion.nl can be found here.


Acknowledgements



Thanks to:


Also:

  • DMARC Digests, for pointing out that, while we had proper DKIM keys, one domain wasn't signing emails. (June 2025)
  • AppMailDev, for providing a free and solid resource to prove that DKIM signed emails work. (June 2025)