Kviklet
Back to website

Security and Vulnerability Disclosure

Last updated: August 28, 2026

Security is important to Kviklet. We welcome responsible reports of suspected security vulnerabilities affecting Kviklet software, the Kviklet website, or other systems operated by Kviklet UG (haftungsbeschränkt).

Reporting a Vulnerability

For vulnerabilities affecting the official Kviklet repository, please use GitHub's private **Report a vulnerability** feature, or email:

security@kviklet.dev

Please include, where available:

  • a clear description of the suspected vulnerability;
  • the affected product, version, component, repository, or URL;
  • steps needed to reproduce the issue;
  • the potential security impact; and
  • your contact details for follow-up questions.

Please do not include vulnerability details in public GitHub issues, discussions, pull requests, social media, or other public forums.

We process personal data submitted with vulnerability reports as described in our Privacy Policy.

Protecting Sensitive Information

Do not include personal data, customer data, production credentials, database contents, access tokens, or other confidential information unless it is strictly necessary to explain the issue. If sensitive information is required, contact us first so that we can agree on a suitable secure transfer method.

If you encounter personal, customer, or other confidential data while investigating an issue, stop accessing it, do not copy or retain it, and notify us promptly.

Responsible Testing

You may test Kviklet software in a self-hosted environment that you own or are expressly authorized to use. Use test data and accounts wherever possible.

Do not test customer-operated Kviklet installations, customer infrastructure, https://kviklet.dev, or other systems operated by Kviklet UG unless you have explicit authorization. Avoid activities that could disrupt services, alter or destroy data, access third-party data, establish persistent access, or otherwise harm another party.

This policy does not authorize testing of systems operated by Kviklet UG or its customers and does not create a legal safe harbor.

Scope

Reports may concern:

  • Kviklet software published by Kviklet UG;
  • https://kviklet.dev and systems operated by Kviklet UG; or
  • official Kviklet releases, container images, and repositories.

Customer-operated, self-hosted Kviklet installations and customer infrastructure are controlled by the relevant customer. Issues caused by the Kviklet product itself may still be reported to us.

Third-party services are outside our control unless the issue results from Kviklet's implementation or configuration of that service.

Disclosure and Compensation

Please allow us a reasonable opportunity to investigate and address a reported issue before publishing technical details.

Kviklet does not currently operate a bug-bounty program. A report does not create an entitlement to payment, a reward, or other compensation.

© 2026 Kviklet
Legal NoticePrivacy PolicySecuritySoftware License Agreement