Responsible disclosureFound something
Found something
security-sensitive?
Please report it privately first so there is a chance to investigate and protect users.
Contact
Send security reports to security@kelyro.net.
What to include
- A clear description of the issue and its impact.
- Steps to reproduce it.
- The Kelyro Auth version and device / HarmonyOS version used for testing.
- Any proof-of-concept details needed to understand the issue.
Please do not include real OTP secrets, Recovery Codes or other users’ private data.
Good-faith testing
Avoid destructive testing, privacy violations, service disruption, social engineering and attempts to access data that is not yours.
Disclosure
Please allow reasonable time to investigate and address a report before public disclosure. If a public advisory is needed, coordinated wording helps users understand the risk without unnecessary alarm.