SUSPECTED A BREACH?  INCIDENT RESPONSE  contact@katitisecurity.com
VICTORIA +04MAHÉ · SEYCHELLES
LegalLast updated 22 July 2026

Responsible Disclosure Policy

We are a security firm, so we welcome reports of genuine security issues in our own systems. This policy explains how to tell us, what we ask of you, and what you can expect from us in return. It applies to systems operated by Katiti Security, not to our clients.

01How to report

If you believe you have found a security vulnerability in a Katiti Security system, please email contact@katitisecurity.com with the subject line marked Security disclosure. Include enough detail for us to reproduce the issue, such as the affected system, a description of the flaw, and clear steps or a proof of concept. Please give us a reasonable time to investigate and fix the issue before making it public.

02Scope

This policy covers systems that Katiti Security owns and operates, including this website and our own tools. It does not authorise any testing of our clients or their systems, and it does not cover third-party services we rely on. If you are unsure whether something is in scope, ask us first.

03What we ask of you

To keep everyone safe and lawful, we ask that you act in good faith and within these limits.

  • Do not access, modify, or delete data that is not yours, and stop as soon as you have demonstrated a flaw.
  • Do not degrade our services, run denial-of-service attacks, or use automated scanning that disrupts availability.
  • Do not use social engineering, physical intrusion, or attacks against our staff.
  • Do not publicly disclose the issue until we have had a reasonable opportunity to address it.
  • Keep any details of the vulnerability confidential until it is resolved.

04Our commitment to good-faith researchers

If you make a good-faith effort to comply with this policy, we will treat your research as authorised, we will not pursue legal action against you for it, and we will work with you to understand and resolve the issue quickly. We will acknowledge your report, keep you informed of progress, and credit you if you wish once the issue is fixed. We do not currently operate a paid bounty, but we value and recognise responsible disclosure.

05What is not authorised

Acting outside this policy, including accessing other people's data, disrupting our services, or testing systems that are not ours, is not authorised and may be unlawful. This policy is a statement of how we handle good-faith security research on our own systems, and it does not grant permission to test anything else.