Security
Report a security problem
If you think you found a vulnerability in Keplar, email team@keplar.one. A machine-readable copy of this policy is at /.well-known/security.txt.
What to send
- What you found, where (URL or API route), and the steps to reproduce it.
- The impact as you understand it. A short proof of concept is plenty.
- How to reach you if you want a reply. We read every report by hand and will answer as soon as we can, but we cannot promise a response time.
Ground rules
- Test only against accounts you own. Do not read, change or delete other people's data. If you reach someone else's data by accident, stop and tell us.
- No denial-of-service, spam, social engineering of our team or users, or physical attacks.
- Give us a reasonable chance to fix the problem before you publish details.
- Do not include real personal data in your report.
If you follow these rules in good faith, we will not pursue action against you for the research. This is a statement of intent by a small team, not a legal safe-harbor agreement.
Rewards
We do not run a bug bounty and do not pay for reports. We are glad to thank you by name in release notes if you want that.
What protects your account today
- Connections use HTTPS, with HSTS and standard browser security headers.
- Passwords are stored as salted scrypt hashes, never in plain text. Sign-in, sign-up and reset requests are rate limited.
- Optional two-factor sign-in with any authenticator app (TOTP), with one-time recovery codes. Turn it on in Account.
- You can see every device signed in to your account and sign out of one or all of them on your Account page. A password reset signs out your other devices.
- When your account signs in from a browser or operating system it has not used before, we email the address on the account with a link that signs out every device.
- Tokens for apps you connect are encrypted before they are stored.
- You can download your data and delete your account from the Account page.
What we do not have
- We hold no security certifications (no SOC 2, ISO 27001 or similar) and have not had an independent audit or penetration test.
- Optional passkeys (fingerprint, face or device PIN) as an extra way to log in; a passkey login counts as two factors. Add one in Account. Two-factor sign-in and passkeys are both optional, so accounts that have turned on neither are protected only by their password, email link or Google/Microsoft login.
We will update this page when that changes, and not before.