At Kiwibit, we take the security of our products, services, and user data seriously. We welcome good-faith reports from security researchers and the broader security community. By working with researchers, we can identify, validate, and address potential vulnerabilities more effectively.
This policy explains which Kiwibit systems are in scope, how to report a potential vulnerability, what testing is allowed, and how we coordinate disclosure.
In-Scope Systems
This policy applies only to systems, products, and services that Kiwibit owns, operates, or explicitly authorizes for security testing, including:
· The official Kiwibit website, including kiwibit.com and Kiwibit-operated subdomains.
· The Kiwibit mobile app for iOS and Android.
· Kiwibit cloud services and APIs, including IoT device management, account and authentication services, data interfaces, and log interfaces.
· Kiwibit devices and firmware, including network cameras and smart bird feeders, and related network configuration, firmware updates, logs, and local or remote debugging functions.
· Real-time audio and video features, including IoT real-time communication, signaling, streaming, playback, peer-to-peer (P2P) and relay services, and media storage.
· Authentication and identity mechanisms used by Kiwibit products and services.
If you are not sure whether a system, endpoint, app feature, device, or service is in scope, please contact us before beginning your research.
Out-of-Scope Systems and Testing
The following systems and activities are not authorized under this policy:
· Systems, services, websites, platforms, or infrastructure owned or operated by third parties, even if they are linked to or integrated with Kiwibit.
· Testing against employee accounts, internal corporate systems, or non-public infrastructure.
· Physical attacks, destructive device testing, or testing devices that you do not own or have permission to test.
Social engineering, phishing, vishing, smishing, impersonation, or attempts to access employee or customer accounts.
· Denial-of-service testing, distributed denial-of-service testing, stress testing, load testing, or any activity that may degrade service availability.
· Brute-force attacks, credential stuffing, password spraying, or use of leaked, stolen, or purchased credentials.
· Malware, persistence mechanisms, pivoting, command-and-control activity, or attempts to maintain unauthorized access.
· Accessing, copying, modifying, deleting, downloading, or retaining data that does not belong to you.
· Publicly disclosing, selling, trading, or sharing vulnerability details before Kiwibit has had a reasonable opportunity to investigate and remediate the issue.
How to Report a Vulnerability
If you believe you have discovered a potential security vulnerability, please email us at support@kiwibit.com with the subject line:
Security Vulnerability Report
To help us review your report quickly, please include as much of the following information as possible:
· The affected product, website URL, app version, firmware version, device model, or API endpoint.
· A clear description of the vulnerability and its potential security impact.
· Step-by-step instructions to reproduce the issue.
· Expected results and actual results.
· Screenshots, screen recordings, logs, crash reports, or network captures, if helpful.
· Proof-of-concept details or code, if necessary to demonstrate the issue.
· The test account, device, or environment used during your research.
· Your contact information and, if encrypted communication is needed, your preferred secure contact method.
Please mask or remove personal information, payment information, credentials, tokens, private keys, and other sensitive data from your report whenever possible. If sensitive information is necessary to explain the issue, do not send it by email until we confirm an appropriate secure method.
Research Guidelines
To help protect Kiwibit users and services, researchers must:
· Test only systems and products that are in scope.
· Use only the minimum testing necessary to confirm a vulnerability.
· Use your own accounts, devices, and data whenever possible.
· Stop testing immediately if you encounter personal information, payment information, credentials, private content, source code, production data, or other sensitive information.
· Avoid privacy violations, data loss, service interruptions, performance degradation, device damage, or additional costs to Kiwibit or its users.
· Do not exploit a vulnerability beyond what is required to verify its existence.
· Do not attempt to access, modify, delete, download, retain, or disclose data that is not your own.
· Comply with all applicable laws and regulations.
· Keep vulnerability details confidential until we have coordinated disclosure with you.
Good-Faith Research
Kiwibit intends to work constructively with researchers who act in good faith and follow this policy. If your research complies with this policy, we will treat your report as authorized security research to the extent permitted by applicable law.
This policy does not authorize activity that is illegal, harmful, destructive, deceptive, outside the stated scope, or directed at third-party systems. Activity that does not comply with this policy may result in account restrictions, service restrictions, or other action.
Response and Remediation Process
After we receive a vulnerability report, we aim to follow this process:
1. Acknowledge receipt of the report.
2. Review the report and determine whether the issue is in scope.
3. Classify the potential severity and reproduce the issue where possible.
4. Develop a fix, mitigation, or other appropriate response.
5. Coordinate with affected vendors, service providers, or platforms if needed.
6. Confirm remediation and coordinate public disclosure where appropriate.
Our target response timelines are:
· Critical issues: Initial response and classification within 48 hours.
· High-severity issues: Initial response and classification within 3 business days.
· Other issues: Response or action plan within 7 business days.
We aim to complete fixes or mitigations within 90 calendar days where feasible. Some issues may require more time depending on severity, technical complexity, third-party dependencies, product release schedules, or regulatory requirements.
Public Disclosure
We support coordinated vulnerability disclosure. Please do not publicly disclose technical details, exploit code, screenshots, logs, or proof-of-concept materials before Kiwibit has confirmed that the issue has been fixed or mitigated, or before we have agreed on a disclosure timeline.
If you believe public disclosure is necessary before remediation is complete, please contact us first so we can discuss a coordinated approach.
Kiwibit may publish a security advisory, release note, or summary after an issue is resolved. We will not publish your name, contact information, or private communications without your permission.
Submitted Materials
By submitting a vulnerability report, you give Kiwibit permission to use the information you provide for security review, investigation, reproduction, remediation, mitigation, communication with affected vendors or service providers, and coordinated disclosure.
Please do not submit information that you do not have the right to share. Vulnerability reports should be accurate, made in good faith, and limited to information necessary for Kiwibit to understand and address the issue.
Rewards and Compensation
Kiwibit does not currently offer a public bug bounty program. Submitting a vulnerability report does not create a right to payment, reward, employment, contract, or other compensation.
Any reward, recognition, or compensation must be agreed to by Kiwibit in writing before it is provided.
Policy Updates
Kiwibit may update this Vulnerability Disclosure Policy from time to time. The updated version will be posted on this page, and the “Last updated” date will be revised accordingly.
Contact Us
For security issues, please email: support@kiwibit.com
Please use the subject line "Security Vulnerability Report" so we can route your message appropriately.
Comments
0 comments
Please sign in to leave a comment.