Skip to content

Updated 9 October 2026

Security and responsible disclosure

01Our approach

KUZUB LTD makes software that companies rely on in their work, and the security of that software and of our customers' data is part of its quality. We welcome reports of security vulnerabilities from anyone. This policy explains how to report one, how to research safely, the legal protection we give to research that follows this policy, and what we commit to in return.

KUZUB LTD is a private limited company registered in Scotland with company number SC890997. Its registered office is at Suite 2/3, 48 West George Street, Glasgow G2 1BP, United Kingdom.

A working day is Monday to Friday, except public holidays in Scotland.

02What this policy covers

This policy covers kuzub.co.uk and its subdomains, and any future application hosts under kuzub.app.

Until Caldaia Studio publishes its own vulnerability disclosure policy on caldaiastudio.com, this policy also covers research on caldaiastudio.com and its subdomains, and reports about Caldaia Studio also go to security@kuzub.co.uk.

This policy does not cover services that other companies run, such as hosting, email, payment and AI providers, even where those services appear under our domain names or are used by our products. Please report problems in those services to the company that runs them. If you are not sure which policy covers a system, or whether a system is ours, ask us at security@kuzub.co.uk before you test it.

03How to report a vulnerability

Write to security@kuzub.co.uk, in English or Ukrainian. If you believe the vulnerability is being exploited now, or that it exposes personal data, say so at the start of your message.

Please tell us which website, application or address is affected, and what the vulnerability is and what an attacker could do with it. Give the steps to reproduce it, with any proof-of-concept code or screenshots. Tell us when you tested and, if you can, the IP address you tested from, so that we can tell your activity apart from an attack. Tell us whether, and how, you would like to be credited.

We do not publish an encryption key. If your report contains sensitive detail, send a short first message without it, and we will agree with you a secure way to send the rest.

If you came across personal data or confidential information, tell us what kind of data it was, but do not send us copies of it.

04How to research safely

Use only accounts that you created yourself for testing. Do not access, change or delete data that does not belong to you. If a vulnerability gives you access to such data, go no further than you need to confirm the vulnerability, then stop and report it to us. Do not use one vulnerability to reach other systems or data. Delete any data you obtained once you have reported the vulnerability.

Do not do anything that could disrupt our services or the people who use them: no denial-of-service testing, no automated vulnerability scanners, no attempts to guess or reuse passwords, and no more than one request per second. Our products are in use by customers, and your testing must not affect them.

Do not try to deceive our people, customers or partners, for example by phishing. Do not attempt physical access to any premises or equipment, and do not test payments with real payment cards.

Keep the vulnerability confidential until it is fixed or the disclosure period below has ended. Do not ask for payment or any other benefit in return for not disclosing it.

This policy does not authorise research by, or for the benefit of, anyone in Russia or Belarus or named on a sanctions list referred to at kuzub.co.uk/legal.

05Safe harbour

We treat research that you carry out in good faith and in line with this policy as authorised by us, including for the purposes of the Computer Misuse Act 1990 and similar laws elsewhere, and we will not bring legal action against you, or ask the police to investigate you, for that research.

Our authorisation covers only the systems and data that we own or control. We cannot authorise testing of systems that other companies run. If a third party brings legal action against you for research that followed this policy, we will make it known that you acted with our authorisation.

If your research exposed personal data, the law may require us to notify the Information Commission and the people whose data was exposed. We will not name you in such a notification unless the law requires it.

This protection applies only while you follow this policy. If you are unsure whether something you plan to do is allowed, ask us first at security@kuzub.co.uk.

06Out of scope

We do not treat the following as vulnerabilities under this policy unless you show how they can be used to harm the security of our services or our customers' data.

These are findings from automated tools without a working exploit; missing security headers or cookie attributes; clickjacking on pages with no sensitive action; and cross-site scripting that can only affect the person who enters it.

They also include the configuration of email authentication records such as SPF, DKIM and DMARC; disclosure of software versions or of information that is already public; missing rate limits on actions that carry no risk; and issues that require a compromised device or an outdated, unsupported browser.

07What we commit to

We acknowledge your report within two working days and aim to tell you within 10 working days whether we can reproduce the vulnerability and what we will do next. We keep you informed while we work on it, and tell you when it is fixed.

We handle your report in confidence. We use your name, contact details and report only to deal with the report, to keep you informed of our progress and, if you wish, to credit you. The privacy notice at kuzub.co.uk/privacy explains how we handle personal data in messages sent to us.

08Coordinated disclosure

We ask you not to disclose a vulnerability publicly until we have fixed it or until 90 days have passed since your report, whichever comes first. If a fix needs longer, we will explain why and ask you to agree a later date. Please send us your write-up five working days before you publish it, and leave out any personal data or confidential information you came across.

09Recognition

We do not run a bug bounty programme, and we do not pay for reports. We credit researchers who wish to be named: once the vulnerability you reported is fixed, and with your agreement, we name you on this page.

10Personal data breaches

If a security incident leads to a personal data breach, we follow the law that applies to it. Where the law requires it, we notify the Information Commission (ico.org.uk) and, where EU data protection law applies, the supervisory authorities it requires, without undue delay and, where feasible, within 72 hours of becoming aware of the breach. We tell the people affected without undue delay if the breach is likely to result in a high risk to their rights and freedoms. Where we process data on a customer's behalf, we notify that customer as our agreement with it requires.

11Other security questions

Questions about the security of our products, for example from a customer's security team, can also be sent to security@kuzub.co.uk. Other enquiries go to hello@kuzub.co.uk. The contact details in this policy are also published in machine-readable form at kuzub.co.uk/.well-known/security.txt.

12Changes to this policy

We may update this policy, and the date at the top shows when it last changed. Research carried out under an earlier version is covered by the version in force when the research was carried out. This is version 1, the first version published by KUZUB LTD.