Security
Draft pending legal review. Values in [brackets] are being finalised.
We welcome reports from security researchers. If you've found a vulnerability in Kuro VPN, please tell us before anyone else.
How to report
Email [email protected] with what you found, how to reproduce it and what an attacker could do with it. Please don't include anyone else's data.
We will:
- confirm we've received your report within 3 working days,
- tell you within 10 working days whether we can reproduce it and what happens next,
- fix serious issues as fast as we can and keep you updated,
- credit you on this page once it's fixed, if you'd like.
Safe harbour
We won't take legal action against good-faith research that follows this policy: you only access what you need to show the problem, you don't degrade our service or other people's, you don't use social engineering or physical attacks, and you give us reasonable time (90 days by default) to fix the issue before publishing.
Scope
In scope: the Kuro VPN apps, this website, the account portal, our API at api.kurovpn.com and our
VPN servers.
Out of scope: denial of service, volume or rate-limit testing, reports from automated scanners without a working exploit, missing security headers with no demonstrated impact, and our partners' websites.
Rewards
We don't run a paid bug bounty yet. We do credit everyone who helps, and we'll say here when that changes.
Our security.txt lists the same contact for automated tools.