Security process · candidate

KYN security reporting

This exact content is staged for explicit KC activation. It is public for review but is not active participant policy yet.

Content SHA-256
sha256:1864c07ab9489f0277664c268857a9db7cc6bdd71441af78ab8880f31ed8eceb

KYN security reporting

Status: proposed public-beta process · not active until the KYN release is activated

Please report a suspected KYN vulnerability privately to kc@uspartyparty.com. Use a subject line beginning KYN SECURITY and include the affected URL or component, what you observed, and a safe way to reproduce it.

Do not include participant private keys, recovery codes, service credentials, identity evidence, personal data, active exploit payloads, or unnecessary private graph details in ordinary email. Ask for a more suitable secure channel first when the report requires sensitive material.

Response targets

  • acknowledge a report within three business days;
  • provide an initial status or request for more information within seven business days;
  • prioritize containment when active participant harm or unauthorized access is plausible; and
  • publish a public-safe advisory after containment and affected-version review when disclosure would help participants or downstream operators.

These are beta operating targets, not guaranteed service levels. If the normal channel appears compromised, pause interaction with the affected feature and use a separately established contact channel for KC Streich or Five Letter Agency.

Good-faith research that avoids privacy harm, service disruption, persistence, social engineering, and data extraction is welcome. This statement does not grant permission to access another person's records or systems.