Skip to content
Legal Center

KokuaOS — Vulnerability Disclosure Policy

Effective July 18, 2026 · Version 1.0

How to report security vulnerabilities to KokuaOS, what testing is authorized and prohibited, and the conditions of the good-faith safe harbor.

Capitalized terms have the meanings in the KokuaOS Definitions Schedule (kokuaos.com/legal/definitions).

1. Purpose

KokuaOS values the work of the security-research community and welcomes reports of suspected vulnerabilities in the Platform and the Services. This Policy explains how to report a vulnerability, what security testing is and is not authorized, and the limited, conditional safe harbor that applies to good-faith research conducted within these rules. This Policy is not a bug-bounty program and does not offer any reward (see Section 9).

2. How to report

Report suspected vulnerabilities to security@kokuaos.com. Please include enough information for KokuaOS to reproduce and assess the issue, such as: a description of the vulnerability and its potential impact, the affected URL, endpoint, or component, the steps or proof-of-concept needed to reproduce it, and any relevant logs or screenshots. Please submit reports in English, keep them confidential until resolved (see Section 7), and do not include more sensitive data than is necessary to demonstrate the issue. If you need to transmit sensitive details, ask us for a secure channel.

3. Authorized testing (scope)

Authorized testing under this Policy is limited to non-destructive security testing that you perform:

  • against your own account, tenant, or test data, or against a test account you are expressly authorized to use; and
  • only to the extent necessary to find and demonstrate a vulnerability, using the minimum interaction required.

If you are a Customer, Service Provider, or Reseller, this Policy authorizes testing of your own environment only and does not authorize testing that affects other tenants, the shared Platform beyond your tenant, or any Third-Party Service.

4. Prohibited testing and conduct

The following are out of scope and prohibited, and are not covered by the safe harbor in Section 8:

  • accessing, modifying, or deleting data that is not yours, or attempting to access another tenant's or user's data;
  • data exfiltration — copying, retaining, transferring, or disclosing any data that is not your own;
  • denial-of-service or any test that degrades, disrupts, or impairs the availability or integrity of the Services, and automated scanning, brute-forcing, or high-volume traffic that has that effect;
  • social engineering (including phishing, vishing, or smishing) of KokuaOS personnel, customers, partners, or users, and any physical-security or on-site testing;
  • testing the systems, networks, or accounts of BYO Providers, carriers, Subprocessors, or other Third-Party Services, which are not KokuaOS's to authorize;
  • introducing malware, backdoors, or persistent access; making unauthorized configuration changes; or attempting to pivot to systems beyond the reported vulnerability;
  • sending spam or unsolicited messages, or using the AI Employees or Communication Channels to place live calls or messages to non-consenting third parties as a test; and
  • any activity that violates applicable law, the Acceptable Use Policy (kokuaos.com/legal/aup), or the Agreement.

5. Rules for handling data during research

If, during authorized testing, you inadvertently access data that is not yours or that appears to be Personal Data or Confidential Information, you must stop immediately, refrain from viewing, copying, or storing more than the minimum needed to document that access occurred, promptly report it to security@kokuaos.com, and delete any such data in your possession upon request. Do not use, retain, or disclose it for any other purpose.

6. What to expect from KokuaOS

KokuaOS will make good-faith efforts to acknowledge a report, triage and validate the issue, keep you reasonably informed of status, and remediate confirmed vulnerabilities on a risk-prioritized basis. KokuaOS does not commit to specific response or remediation timeframes in this Policy. With your permission, KokuaOS may credit you once an issue is resolved.

7. Coordinated disclosure

Please give KokuaOS a reasonable opportunity to investigate and remediate before disclosing a vulnerability to anyone else, and do not publicly disclose a vulnerability, or share it with third parties, until KokuaOS confirms it has been resolved or the parties agree in writing on a coordinated disclosure. KokuaOS will work with you in good faith on disclosure timing. This Section does not prevent you from reporting a matter to a governmental authority where you are legally entitled to do so.

8. Good-faith safe harbor (limited and conditional)

If you conduct security research and vulnerability disclosure in good faith and in full compliance with this Policy, KokuaOS will consider that activity to be authorized, will not pursue or support legal action against you for it, and will not report it to law enforcement, in each case in connection with your compliant research. To the extent your compliant activity would otherwise breach the Agreement or the Acceptable Use Policy, KokuaOS waives that breach solely for such activity. This safe harbor is subject to the following conditions and limits:

  • it applies only to activity that stays within Sections 3 through 7 and does not include any prohibited activity in Section 4;
  • it is not a waiver of, and does not extend to, the rights of any third party, including other customers, BYO Providers, Subprocessors, carriers, or other Third-Party Services — you are responsible for obtaining any authorization those parties require, and you must not test their systems;
  • it does not authorize you to violate any applicable law, and it provides no protection for activity that is unlawful independent of this authorization;
  • it does not transfer any ownership, license, or other right in the Platform, the Services, or KokuaOS intellectual property, and does not permit you to access, use, or retain data except as strictly necessary under this Policy; and
  • if your activity falls outside this Policy, KokuaOS reserves all rights, and whether any authorization applies will be evaluated on the specific facts. If you are unsure whether an action is authorized, contact security@kokuaos.com before proceeding.

Nothing in this Policy limits KokuaOS's ability to comply with legal process or to protect the Services and others from harm.

9. No bounty unless expressly offered

KokuaOS does not offer monetary rewards, bounties, or other compensation for vulnerability reports unless KokuaOS expressly offers a reward in a separate, written program that identifies the applicable scope and terms. Submitting a report does not entitle you to any payment. If KokuaOS operates a paid program at any time, its published terms govern that program.

10. Changes and contact

KokuaOS may update this Policy from time to time as described in the Master Terms & Conditions; the version in effect when you conduct testing applies to that activity. Reports and questions may be directed to security@kokuaos.com. The current version of this Policy is published at /legal/vulnerability-disclosure.

See it liveBook a demo