Security & Responsible Disclosure
Last updated: September 2026
Kronus Instruments takes the security of inspection data seriously. If you believe you have found a vulnerability in any of our systems, we want to hear from you. This page explains what is in scope, how to report, what you can expect from us, and the protection we offer good-faith researchers. A machine-readable version is published at /.well-known/security.txt (RFC 9116).
Scope
The following are in scope for responsible disclosure:
- The public website and web portal at
kronusinstruments.comand its subdomains. - The Kronus Field iOS application distributed through TestFlight and the App Store.
- Backend APIs, Cloud Functions and storage buckets that these clients talk to.
Out of scope:
- Denial-of-service, volumetric or resource-exhaustion testing of any kind.
- Social engineering, phishing or physical attacks against our staff, customers or facilities.
- Findings in third-party services we do not operate (Google Cloud, Firebase, Stripe, Apple), unless caused by our configuration.
- Reports from automated scanners with no demonstrated impact, missing best-practice headers with no exploit, and clickjacking on pages with no sensitive actions.
- Accessing, modifying or deleting data that does not belong to you. If you reach another customer's data, stop, record the minimum needed to demonstrate the issue, and report it immediately.
How to report
Email info@kronusinstruments.com with the subject line Security vulnerability report. Please include:
- The affected product, URL or endpoint, and the version or build number if known.
- Step-by-step reproduction instructions, a proof of concept, and the impact you believe it has.
- Whether you have shared the finding with anyone else and how you would like to be credited, if at all.
If your report contains sensitive material, ask us for an encryption key in your first message and we will provide one before you send details.
What to expect
- Acknowledgement within 3 business days of receipt.
- Triage and initial assessment within 10 business days, including a severity rating and whether we consider the issue in scope.
- Resolution of confirmed critical and high-severity issues within 90 days, and a status update at least every 30 days until then.
- Coordinated disclosure: we ask that you give us 90 days from acknowledgement before publishing details, and we will agree a disclosure date with you when a fix ships earlier.
We do not currently run a paid bug bounty programme. With your permission we are happy to credit researchers who report valid issues.
Safe harbor
We consider security research conducted in accordance with this policy to be authorised. Provided that you act in good faith, avoid privacy violations, data destruction and service disruption, do not exploit a finding beyond what is necessary to demonstrate it, and give us a reasonable time to remediate before disclosure, Kronus Instruments will not initiate or support legal action against you for your research, and will not refer your activity to law enforcement. If a third party initiates legal action related to research conducted under this policy, we will make it known that your activity was authorised.
This policy does not authorise you to break any law, and it cannot bind third parties. If you are unsure whether a test is covered, ask us first.
Contact
Kronus Instruments, Inc., {{REGISTERED_ADDRESS}}. Security correspondence: info@kronusinstruments.com.
