Reporting a security vulnerability
How to responsibly disclose a security issue — routed separately from general support.
Found a potential security issue in PTERI, the Kakr Labs Wallet, our APIs, or this support portal? Please report it to us directly rather than disclosing it publicly first — this keeps everyone, including other customers, safe while we investigate and fix it.
How to report
- Use our ticket form and select "Security / Vulnerability Report" as the category — this routes it separately from general support instead of sitting in the same queue as a billing question.
- Or email contact@kakr.ai with a subject line starting with "SECURITY:".
- Machine-readable reporting details are also published at /.well-known/security.txt (the emerging standard security researchers' tools check automatically).
What to include
- A clear description of the issue and its potential impact
- Step-by-step instructions to reproduce it
- Any relevant request/response data, screenshots, or proof-of-concept code
- The component affected (wallet app, API, support portal, etc.) and, if applicable, an account or wallet address used for testing
Responsible disclosure guidelines
To keep this a good-faith process for everyone:
- Only interact with accounts and data you own, or that you have explicit permission to test
- Don't access, modify, or exfiltrate data beyond what's strictly needed to demonstrate the issue
- Avoid actions that could degrade service for other users (no automated scanning or load-testing against production without prior written permission)
- Give us a reasonable window to investigate and remediate before any public disclosure
We review every report that comes in through these channels. For anything else — account help, billing, general questions — please use the regular support ticket flow or ask our AI assistant.
