Coordinated Vulnerability Disclosure Procedure 

Kuori is committed to protecting the security of our products and customers. We encourage security researchers, customers, partners and other stakeholders to responsibly report potential security vulnerabilities to us.

Our Coordinated Vulnerability Disclosure (CVD) procedure enables us to investigate reported vulnerabilities, coordinate remediation and communicate relevant security information.

How to report a vulnerability

If you believe you have identified a security vulnerability in a Kuori product, please provide us with as much relevant information as possible.

A vulnerability report should preferably include: 

  • Description of the vulnerability
  • Affected product
  • Affected software or firmware version
  • Steps to reproduce the vulnerability
  • Potential impact
  • Proof-of-concept or supporting information, where available
  • Contact information for follow-up communication

Submit a record

 Please include as much of the information listed on this page as possible so we can assess your report quickly. You can submit your report via the web form using the button below or by email at security(at)kuori.tech. 

What happens after a report?


01   Kuori acknowledges receipt of the report. 


02    The reported vulnerability is assessed and, where appropriate, validated. 


03    The potential impact and severity are evaluated. 


04    Affected products and versions are identified. 


05    An appropriate remediation is developed and validated.  


06    Relevant security information is communicated where necessary. 

Responsible disclosure


We ask reporters to avoid activities that could compromise customer data, disrupt services or negatively affect the availability or integrity of Kuori products.

If testing is required to demonstrate a vulnerability, please limit testing to the minimum necessary to verify and document the issue.