Report a Vulnerability
Last updated: July 2026
Knowledge Catalyst builds trust infrastructure — verifiable credentials, digital wallets, and the systems that issue and verify them. We value the work of security researchers and welcome reports of genuine vulnerabilities in the systems covered by this policy. This is a responsible-disclosure policy, not a bug bounty programme; we do not currently offer monetary rewards, but will, with your consent, acknowledge your contribution.
1. Scope
This policy applies to internet-facing systems owned and operated by Knowledge Catalyst, including knowledgecatalyst.io and its subdomains, the Knowledge Catalyst web application and public APIs, and the KC Trust Rail / credential-verification services. The following are explicitly out of scope — do not test them:
- Systems, services, or data owned by our customers, partners, or third-party providers (cloud, email, DNS, payment), even where they carry KC branding.
- Any KC staff member, contractor, office, or physical premises.
- Third-party services we link to but do not operate.
- If you are unsure whether a system is in scope, ask us first before testing.
2. Out-of-scope report types
Absent a concrete, demonstrated impact, the following are generally not treated as reportable vulnerabilities:
- Missing HTTP security headers, cookie flags, or TLS configuration findings without a working exploit.
- CSRF on unauthenticated or low-impact forms; username/account enumeration.
- Missing rate limiting where another mitigation exists (e.g. login already protected by MFA).
- Clickjacking without a sensitive state change; OPTIONS/TRACE enabled; autocomplete behaviour.
- Output of automated scanners without a validated, exploitable finding; self-XSS; issues requiring physical access or an already-compromised account.
- Social-engineering or phishing susceptibility of staff or users.
3. Rules of engagement
To qualify for the safe-harbour protections in Section 5, you must:
- Act in good faith, only to identify and report vulnerabilities, and stay within scope.
- Minimise harm: access only the minimum data necessary to demonstrate the issue. Do not access, copy, modify, delete, exfiltrate, or store data that is not your own.
- Stop immediately if you encounter personal, credential, or confidential data, and tell us in your report — do not view or retain it.
- Keep the issue confidential until we confirm it is remediated and give written consent to disclose.
- Use your own test accounts and data.
- You must NOT: perform denial-of-service, load, or brute-force testing; run high-volume automated scans that degrade services; use social engineering or attempt physical intrusion; deploy malware or any destructive payload; pivot to other systems or maintain access; or demand payment as a condition of disclosure.
4. How to report
Use the secure form on this page. It is transmitted over HTTPS; for sensitive details you may additionally PGP-encrypt the report body using the KC public key shown on this page. Please include: a clear description and the affected URL/endpoint/component; step-by-step reproduction and a minimal proof of concept; the potential impact; and, optionally, your name for acknowledgement. Submit one issue per report and do not include real personal data.
5. Safe harbour
If you make a good-faith effort to comply with this policy, Knowledge Catalyst will regard your research as authorised, will not pursue or support legal action against you for accidental, good-faith violations arising directly from following it, will work with you to resolve the issue, and will recognise your contribution with your consent. This safe harbour is conditional on your full compliance with Sections 1–4. Knowledge Catalyst expressly reserves all rights regarding any activity that is unlawful, exceeds this policy's scope, harms KC or third parties, or is conducted in bad faith. Nothing here grants rights over systems you do not have permission to test, or waives the rights of our customers, partners, or other third parties.
6. Our response & governing law
We aim to acknowledge your report within 5 business days and to keep you reasonably informed of progress toward a fix; remediation timelines depend on severity and complexity. We may update this policy at any time; the version in effect at the time of your testing applies. This policy is governed by the laws of Singapore, without regard to conflict-of-laws rules.

