Security and vulnerability disclosure
How to report a security problem in Krodium or our services, what is in scope, and the safe harbour we offer for good-faith research.
Last updated 8 October 2026This document is under legal review.
Svayam Incarnation Limited, a company registered in England and Wales, welcomes reports from security researchers and anyone else who finds a weakness in our products. This policy explains what to test, how to tell us, and what we promise in return.
How to report
Email [email protected] with a subject line starting "Security". If you would like to send it encrypted, say so in a short first message and we will arrange it. Please include:
- what you found and the impact you think it has;
- the steps, code or files needed to reproduce it;
- the Krodium version (Krodium menu, About Krodium) and your operating system version, or the address of the affected page or service;
- how you would like to be credited, if at all.
In scope
- The Krodium browser, in its latest released version, including Kraken, the home screen, the media player and other Krodium features.
- krodium.com, including the Krodium Store pages, sign-in, the developer platform and the developer console.
- Our downloads and how they are published, including checksums.
Out of scope
- Problems that come from shared engine code and also affect other browsers built on it. Please still report them to us; we will pass them on to the people who maintain that code and fix our own builds.
- Extensions and apps published by other developers in the Krodium Store. Report harmful listings to [email protected] and we will act; report weaknesses in them to their developers.
- Third-party services we use, such as Cloudflare, unless the issue is in how we use them. Viremail has its own disclosure process.
- Reports from automated scanners without a demonstrated impact, missing best-practice headers with no exploit, self cross-site scripting, clickjacking on pages without sensitive actions, denial of service, social engineering of our staff, and physical attacks.
Rules for testing
- Test only against your own installations and your own accounts.
- Do not access, change, copy or delete data that is not yours. If you reach someone else's data by accident, stop, do not keep it, and tell us.
- Do not degrade our services for others, and do not use automated tools at a rate that could affect them.
- Give us a reasonable time to fix the problem before you share details publicly. We ask for 90 days, or less once a fix has shipped, and we will agree a date with you.
Safe harbour
If you act in good faith and follow this policy, we will consider your research authorised, we will not take legal action against you or ask the authorities to, and we will work with you to understand and fix the problem quickly. If a third party takes action against you for research that followed this policy, we will make it known that your work was authorised by us. This does not authorise anything that would break the law, or testing of systems that are not ours.
What you can expect from us
| Step | Our target |
|---|---|
| Acknowledge your report | Within 3 working days. |
| Initial assessment and severity | Within 10 working days. |
| Fix for critical and high-severity issues | As fast as possible, usually within 30 days. |
| Fix for other issues | Within 90 days, or a clear explanation and plan. |
| Updates to you | At least every 14 days while we work on it. |
With your permission, we credit researchers in the release notes for the fix. We do not currently run a paid bug bounty programme.
Security updates
We publish new builds of Krodium with security fixes, including fixes to the engine, and list them in the release notes (krodium.com/release-notes). Please keep Krodium up to date.