Responsible disclosure

Found something
security-sensitive?

Please report it privately first so there is a chance to investigate and protect users.

Contact

Send security reports to security@kelyro.net.

What to include

  • A clear description of the issue and its impact.
  • Steps to reproduce it.
  • The Kelyro Auth version and device / HarmonyOS version used for testing.
  • Any proof-of-concept details needed to understand the issue.
Please do not include real OTP secrets, Recovery Codes or other users’ private data.

Good-faith testing

Avoid destructive testing, privacy violations, service disruption, social engineering and attempts to access data that is not yours.

Disclosure

Please allow reasonable time to investigate and address a report before public disclosure. If a public advisory is needed, coordinated wording helps users understand the risk without unnecessary alarm.