Security & responsible disclosure
Last updated: October 2026
We take the security of Keepvik and our customers' data seriously. If you believe you've found a vulnerability, we want to hear from you.
Reporting a vulnerability
Email us with details and steps to reproduce. We'll acknowledge your report, keep you updated, and credit you if you'd like once it's fixed. Our machine-readable policy is at /.well-known/security.txt.
Please do
- Give us a reasonable time to fix an issue before disclosing it publicly.
- Only test against your own account and data.
- Avoid privacy violations, data destruction, and any disruption to our service or customers.
Please don't
- Run automated scanners that degrade the service, or attempt denial-of-service.
- Access, modify or delete data that isn't yours.
- Use social engineering, phishing, or physical attacks against our staff or customers.
How we protect your data
Data is encrypted in transit (HTTPS); access codes, device keys and payment tokens are stored only as one-way hashes; the agent can only run fixes from a fixed list after on-device approval; and we apply a strict data-retention schedule. See our privacy policy for details.