Vulnerability Disclosure & Bug Bounty Program
Last updated: 4 September 2026. This policy applies to reports received on or after that date.
Scope
We welcome responsible disclosure of security vulnerabilities in Kosli’s platform and services. Our production environment is app.kosli.com and the supporting APIs. Our marketing site is www.kosli.com. Findings against domains or infrastructure outside these, including retired brands, parked domains and non-production environments, are assessed on their merits but are generally not treated as production issues.
Testing guidelines
When testing, please:
- Only test against accounts you own or have explicit permission to use
- Stop as soon as you have confirmed a vulnerability, and do not access, modify or retain data belonging to other users
- Keep automated testing to a reasonable volume, and avoid anything that could degrade service for our customers
- Give us reasonable time to investigate and fix an issue before disclosing it publicly
If you follow these guidelines, we will treat your research as authorised, work with you to understand and resolve the issue quickly, and will not pursue legal action against you.
Out of scope
The following are excluded from this program:
- Social engineering attacks (phishing, pretexting and similar), unless the vulnerability enables our platform to be used as a vector for social engineering
- Denial of service (DoS/DDoS) attacks or testing
- Username, email or account enumeration, including differences in login or SSO responses between registered and unregistered addresses, unless chained to a demonstrated further impact
- Absent, weak or bypassable rate limiting, unless chained to a demonstrated further impact
More generally, findings that amount to missing hardening controls or best-practice configuration, where no exploitable condition is demonstrated, are treated as Informational and do not qualify for payment. We will still acknowledge them, and we often act on them.
Eligibility
To qualify for a bounty payment:
- The vulnerability must be Medium severity or above (CVSS score)
- The vulnerability must be actually exploitable in our production environment
- The report must include a working proof of concept that we can reproduce
- We must not have existing defence in depth that mitigates the issue
- The finding must be new. We do not pay for duplicates or issues already identified internally, and we can provide dated ticket evidence on request
Where several reported issues share a single underlying cause, we treat them as one finding and make one award.
Severity assessment
We score findings using CVSS v3.1, and we use the Bugcrowd Vulnerability Rating Taxonomy as our reference for how a class of issue is normally classified. Where our assessment differs from the reporter’s, we will share our vector and our reasoning.
Bounty rates
| Severity | CVSS Score | Bounty |
|---|---|---|
| Medium | 4.0 to 6.9 | £250 |
| High | 7.0 to 8.9 | £500 |
| Critical | 9.0 to 10.0 | £1,000 |
Low severity findings (CVSS below 4.0) are appreciated but do not qualify for payment.
Reporting
Please send all reports to security@kosli.com and include:
- Clear description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Any supporting evidence (screenshots, logs, proof of concept)
Please submit one issue per email, and make sure any attachments relate to the issue described.
Our commitment
Integrity is a core value at Kosli. We have a strong track record of working fairly and openly with security researchers, and we’re committed to transparent communication throughout the disclosure process. We will acknowledge receipt, assess the finding, and respond with our determination. If we classify the vulnerability differently than reported, we’ll explain our reasoning and show our working.
Ready to ship at
AI speed, safely?
See how Kosli automates SDLC Governance inside your environment.
Watch it work, end to end
See the platform enterprise teams use to automate governance across build, release, and runtime.
Kosli in action