Big News: Kosli’s achieves Series A milestone with Deutsche Bank as an investor - Read the announcement
New: Kosli Answers is here! AI-powered insights for compliance and security. Learn more →
pad-lock

Vulnerability Disclosure & Bug Bounty Program

Last updated: 4 September 2026. This policy applies to reports received on or after that date.

Scope

We welcome responsible disclosure of security vulnerabilities in Kosli’s platform and services. Our production environment is app.kosli.com and the supporting APIs. Our marketing site is www.kosli.com. Findings against domains or infrastructure outside these, including retired brands, parked domains and non-production environments, are assessed on their merits but are generally not treated as production issues.

Testing guidelines

When testing, please:

  • Only test against accounts you own or have explicit permission to use
  • Stop as soon as you have confirmed a vulnerability, and do not access, modify or retain data belonging to other users
  • Keep automated testing to a reasonable volume, and avoid anything that could degrade service for our customers
  • Give us reasonable time to investigate and fix an issue before disclosing it publicly

If you follow these guidelines, we will treat your research as authorised, work with you to understand and resolve the issue quickly, and will not pursue legal action against you.

Out of scope

The following are excluded from this program:

  • Social engineering attacks (phishing, pretexting and similar), unless the vulnerability enables our platform to be used as a vector for social engineering
  • Denial of service (DoS/DDoS) attacks or testing
  • Username, email or account enumeration, including differences in login or SSO responses between registered and unregistered addresses, unless chained to a demonstrated further impact
  • Absent, weak or bypassable rate limiting, unless chained to a demonstrated further impact

More generally, findings that amount to missing hardening controls or best-practice configuration, where no exploitable condition is demonstrated, are treated as Informational and do not qualify for payment. We will still acknowledge them, and we often act on them.

Eligibility

To qualify for a bounty payment:

  • The vulnerability must be Medium severity or above (CVSS score)
  • The vulnerability must be actually exploitable in our production environment
  • The report must include a working proof of concept that we can reproduce
  • We must not have existing defence in depth that mitigates the issue
  • The finding must be new. We do not pay for duplicates or issues already identified internally, and we can provide dated ticket evidence on request

Where several reported issues share a single underlying cause, we treat them as one finding and make one award.

Severity assessment

We score findings using CVSS v3.1, and we use the Bugcrowd Vulnerability Rating Taxonomy as our reference for how a class of issue is normally classified. Where our assessment differs from the reporter’s, we will share our vector and our reasoning.

Bounty rates

Severity CVSS Score Bounty
Medium 4.0 to 6.9 £250
High 7.0 to 8.9 £500
Critical 9.0 to 10.0 £1,000

Low severity findings (CVSS below 4.0) are appreciated but do not qualify for payment.

Reporting

Please send all reports to security@kosli.com and include:

  • Clear description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Any supporting evidence (screenshots, logs, proof of concept)

Please submit one issue per email, and make sure any attachments relate to the issue described.

Our commitment

Integrity is a core value at Kosli. We have a strong track record of working fairly and openly with security researchers, and we’re committed to transparent communication throughout the disclosure process. We will acknowledge receipt, assess the finding, and respond with our determination. If we classify the vulnerability differently than reported, we’ll explain our reasoning and show our working.

Get started

Ready to ship at
AI speed, safely?

See how Kosli automates SDLC Governance inside your environment.

Watch it work, end to end

See the platform enterprise teams use to automate governance across build, release, and runtime.

Kosli in action