Last updated: 18 August 2026
In plain English: found a security issue in Kelo? Email [email protected] (or [email protected]). Report it in good faith and we will not take legal action against you.
Email [email protected] with enough detail to reproduce the issue: what you found, where, and the steps to trigger it. Screenshots or a short proof-of-concept help. Please give us a reasonable chance to fix it before disclosing it publicly.
Kelo is early-stage and founder-run, so you are dealing with a person, not a queue. We aim to acknowledge your report within a few working days, keep you updated as we investigate, and let you know when it is fixed. We are grateful for every genuine report and happy to credit you if you would like.
If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, will not pursue or support legal action against you, and will work with you to resolve the issue quickly.
The Kelo web application at gokelo.com and its API. Issues in third-party services we rely on (for example Supabase, Vercel, Cloudflare, Stripe, Xero) should be reported to those providers directly, though we are glad to help coordinate.
See also our security overview and privacy policy.