Vulnerability Disclosure Policy

Last updated: 18 August 2026

In plain English: found a security issue in Kelo? Email [email protected] (or [email protected]). Report it in good faith and we will not take legal action against you.

How to report

Email [email protected] with enough detail to reproduce the issue: what you found, where, and the steps to trigger it. Screenshots or a short proof-of-concept help. Please give us a reasonable chance to fix it before disclosing it publicly.

What to expect

Kelo is early-stage and founder-run, so you are dealing with a person, not a queue. We aim to acknowledge your report within a few working days, keep you updated as we investigate, and let you know when it is fixed. We are grateful for every genuine report and happy to credit you if you would like.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, will not pursue or support legal action against you, and will work with you to resolve the issue quickly.

Please do not

  • Access, modify, or delete data that is not yours.
  • Run attacks that degrade the service for others (for example denial of service).
  • Use social engineering, phishing, or physical attacks against our people or providers.
  • Publicly disclose the issue before we have had a reasonable chance to fix it.

In scope

The Kelo web application at gokelo.com and its API. Issues in third-party services we rely on (for example Supabase, Vercel, Cloudflare, Stripe, Xero) should be reported to those providers directly, though we are glad to help coordinate.

See also our security overview and privacy policy.