Skip to content

Security & responsible disclosure

Last updated: August 24, 2026

We take security seriously and welcome reports from researchers acting in good faith. This page describes how to reach us, what we ask in return, and what you can expect from us.

How to report

Email security@completionkit.com.

Please include:

  • A description of the vulnerability and where you found it (URL, endpoint, parameter).
  • Steps to reproduce, concrete enough that we can validate.
  • Any proof-of-concept code or screenshots that help.
  • Your name and a contact handle for follow-up (optional but appreciated).

What we ask

  • Don't access, modify, or delete data that isn't yours. Use a test account.
  • Don't disrupt the Service, no DoS, no automated load testing.
  • Don't share the vulnerability publicly until we've had a reasonable chance to fix it (we aim for 90 days; we'll coordinate if it needs longer).
  • Don't social-engineer our team or our vendors.

What you can expect

We read and triage every report against the current code. Because we receive a steady stream of automated and duplicate submissions, we only follow up with you if your report is valid and something we're going to fix. If you don't hear back, the behaviour is usually already mitigated, working as intended, or below the bar for a change.

  • We reproduce and investigate anything that looks like a genuine issue.
  • We fix confirmed, exploitable issues, at the source if the cause is in the underlying engine or a dependency.
  • We credit you in the acknowledgements below once a fix ships, if you'd like.

Safe harbour

If you make a good-faith effort to comply with this policy during your security research, we will consider your activity authorized and will not pursue civil or criminal action.

Out of scope

  • Reports generated solely by automated scanners with no demonstrated impact.
  • Issues already publicly disclosed.
  • Self-XSS, clickjacking on pages without sensitive actions, missing security headers without a demonstrated exploitable impact.
  • Vulnerabilities in third-party software unless you can show they're exploitable in our context.

Bounty

We don't run a paid bounty programme today. We're happy to offer public credit for significant reports, and we'll revisit a paid programme as the company grows.

Acknowledgements

Thank you to the researchers whose valid reports led to a fix. We're grateful for the time and care they put in.

  • Missing re-authentication for sensitive functionality (CWE-306) (July 2026). Reported and fixed. Reported by Ravi and Soham D. Jadhav.
  • Run-quota concurrency hardening (July 2026). Closed a race where a burst of simultaneous requests could slip a small number of runs past a plan's limit before the usage counter caught up. Reported by Nujella S S N V Ravindra Kumar.

Machine-readable contact info: /.well-known/security.txt.