Responsible Disclosure
If you believe you have identified a security vulnerability affecting Shellvoide or the KLUE platform, we want to hear from you. We are committed to responding promptly and working collaboratively toward resolution, consistent with responsible disclosure practice.
Last updated: August 2026
Shellvoide will not pursue legal action against individuals who report vulnerabilities in good faith, in accordance with this policy, and who avoid accessing or harming user data, degrading our services, or acting maliciously. We consider good-faith security research to be a service to us and to our customers.
In scope
Shellvoide's public website (shellvoide.com)
The KLUE platform (klue.shellvoide.com)
This Trust Center (trust.shellvoide.com)
Shellvoide-owned infrastructure and services
Out of scope
Third-party services we use. Report vulnerabilities in those to their respective owners.
Vulnerabilities in systems that are explicitly out of an engagement's scope.
Test only within the scope described above.
Do not access, modify, or destroy data that does not belong to you.
Do not perform denial-of-service, social engineering, or phishing against Shellvoide staff or customers.
Do not degrade the availability of our services for other users.
Report vulnerabilities promptly once discovered.
Avoid privacy violations; do not access personal data of other users.
A clear description of the vulnerability and its impact
Steps to reproduce, or a proof of concept
The affected asset (URL, endpoint, or component)
Your contact details so we can coordinate disclosure with you
We acknowledge reports within 2 business days.
We provide regular updates as we investigate and remediate.
We coordinate public disclosure with you after a fix is deployed.
PGP key will be published here before launch. For now, plain email is accepted.