Responsible Disclosure

Responsible Disclosure

If you believe you have identified a security vulnerability affecting Shellvoide or the KLUE platform, we want to hear from you. We are committed to responding promptly and working collaboratively toward resolution, consistent with responsible disclosure practice.

Last updated: August 2026

Shellvoide will not pursue legal action against individuals who report vulnerabilities in good faith, in accordance with this policy, and who avoid accessing or harming user data, degrading our services, or acting maliciously. We consider good-faith security research to be a service to us and to our customers.

01

Scope

In scope

Shellvoide's public website (shellvoide.com)

The KLUE platform (klue.shellvoide.com)

This Trust Center (trust.shellvoide.com)

Shellvoide-owned infrastructure and services

Out of scope

Third-party services we use. Report vulnerabilities in those to their respective owners.

Vulnerabilities in systems that are explicitly out of an engagement's scope.

02

Guidelines

Test only within the scope described above.

Do not access, modify, or destroy data that does not belong to you.

Do not perform denial-of-service, social engineering, or phishing against Shellvoide staff or customers.

Do not degrade the availability of our services for other users.

Report vulnerabilities promptly once discovered.

Avoid privacy violations; do not access personal data of other users.

03

What to include in your report

A clear description of the vulnerability and its impact

Steps to reproduce, or a proof of concept

The affected asset (URL, endpoint, or component)

Your contact details so we can coordinate disclosure with you

04

Response expectations

We acknowledge reports within 2 business days.

We provide regular updates as we investigate and remediate.

We coordinate public disclosure with you after a fix is deployed.

05

How to report

PGP key will be published here before launch. For now, plain email is accepted.