KYN security reporting
Status: proposed public-beta process · not active until the KYN release is activated
Please report a suspected KYN vulnerability privately to
kc@uspartyparty.com. Use a subject line beginning
KYN SECURITY and include the affected URL or component, what you observed, and a
safe way to reproduce it.
Do not include participant private keys, recovery codes, service credentials, identity evidence, personal data, active exploit payloads, or unnecessary private graph details in ordinary email. Ask for a more suitable secure channel first when the report requires sensitive material.
Response targets
- acknowledge a report within three business days;
- provide an initial status or request for more information within seven business days;
- prioritize containment when active participant harm or unauthorized access is plausible; and
- publish a public-safe advisory after containment and affected-version review when disclosure would help participants or downstream operators.
These are beta operating targets, not guaranteed service levels. If the normal channel appears compromised, pause interaction with the affected feature and use a separately established contact channel for KC Streich or Five Letter Agency.
Good-faith research that avoids privacy harm, service disruption, persistence, social engineering, and data extraction is welcome. This statement does not grant permission to access another person's records or systems.