Responsible disclosure
Send security reports to security@konduit.gg with scope, impact, and reproduction steps.
Security
If you believe you have found a security issue in Konduit, send enough detail for the team to reproduce and assess it safely.
Send reports to security@konduit.gg. Please include only the information needed to validate the issue.
Konduit keeps TLS validation enabled. Reports about transport, authentication, or credential handling are welcome through the same intake.
Send security reports to security@konduit.gg with scope, impact, and reproduction steps.
Sensitive OAuth and account material follows the secure-storage allowlist architecture.
Launch checks include npm audit review, secret scanning, and a Snyk evaluation path.
Sentry capture stays inert until the marketing-site DSN is provisioned, and events are sanitized before leaving the site.
Konduit keeps TLS verification enabled. Security reports about certificate handling, downgrade risk, redirects, or transport assumptions should include affected URL, environment, and reproduction steps.
OAuth tokens, refresh tokens, JWTs, and secrets are routed through the encrypted-at-rest sensitive-key architecture with allowlisted key names. Plaintext credential storage paths are outside launch policy.
Connected platform flows use scoped OAuth permissions and one-time exchange patterns where platforms support them. Do not send access tokens in screenshots unless the report requires it.
Launch verification includes npm audit review and secret-scanning posture. Snyk evaluation is planned after launch hardening, and no Sentry-specific product telemetry is enabled at launch.