Coordinated Vulnerability Disclosure (CVD) Policy

Our commitment

Kelio (a Kelio SAS brand) attaches great importance to the security of its products. We welcome vulnerability reports made in good faith by security researchers and we undertake to handle them seriously, transparently and within a reasonable timeframe.

Products concerned

This policy applies to Kelio products during their support period. Beyond this period, Kelio may, at its discretion and without any commitment to a timeframe, continue to review received reports.

How to report a vulnerability

Please complete the form below to report a vulnerability.

Languages accepted: French, English
Acknowledgement of receipt: within 48 working hours, with a unique tracking identifier
Anonymous reports are accepted but do not allow for coordinated follow-up.

Our timeframe commitments

CommitmentTimeframe
Acknowledgement of receipt of the report48 working hours maximum
Confirmation of technical qualification10 working days maximum
Agreement on the disclosure timeline15 working days maximum
Notification of patch availabilityWithin 24 hours after deployment to production

Coordinated disclosure

Kelio commits to remediating a vulnerability and coordinating its publication within a maximum timeframe of 90 calendar days from its confirmation. This period may be extended by an additional 30 days in the event of exceptional technical complexity, subject to the reporter’s agreement.
Actively exploited vulnerabilities will be subject to a public security advisory once fixed.

Protection of bona fide researchers (safe harbour)

Kelio undertakes not to initiate civil or criminal legal action against researchers who report a vulnerability in good faith, provided that they:

  • Act solely to the extent necessary to demonstrate the vulnerability.
  • Do not damage, destroy or alter any data or system.
  • Do not disclose the vulnerability before the expiry of the agreed coordination timeframe.
  • Do not exploit the vulnerability for their own benefit or that of a third party.
  • Report the vulnerability as soon as possible via our official channels.

Reporter recognition

Kelio may, at its discretion and depending on the criticality of the reported vulnerabilities, recognise the work of security researchers and grant non-monetary rewards to the most deserving reporters. Kelio reserves the right to implement a structured Bug Bounty programme in the future and will inform reporters via the security portal.

However, it should be noted that no monetary reward will be granted to researchers who have discovered vulnerabilities in the Kelio product.

What is not covered

The following, in particular, are not covered by this policy: unauthorised access to live production systems, any damage to data or systems, exfiltration of personal data, denial-of-service attacks, social engineering or any exploitation for malicious or lucrative purposes.