Report a vulnerability
Found a security vulnerability in the Kuno device, the app, or our backend? Report it to us confidentially — we review every report and protect researchers who act in good faith.
At a glance
- Reports go exclusively to [email protected], not to general support.
- In scope: the Kuno recorder, the companion app, and our EU backend; third-party services are excluded.
- Safe harbor commitment: researchers who act in good faith and follow our rules don't need to fear legal action.
- Initial response within 72 hours, coordinated disclosure after 90 days.
- Never listen to real third-party recordings - that would be a criminal offense under Section 201 StGB.
Security and data sovereignty are at the core of Kuno. If you find a vulnerability, we want to know about it before anyone can exploit it. This policy describes how to report responsibly and what you can expect from us.
How to report
- Send your report to [email protected] — not to general support.
- Describe the vulnerability and include clear steps to reproduce it.
- If you wish, encrypt sensitive details with our PGP key (available on request).
- Wait for our confirmation before sharing details with third parties.
What to include in a report
- Affected component: Kuno device, app version, or backend endpoint
- Step-by-step instructions to reproduce
- Potential impact (e.g., data access, pairing bypass)
- Optional: proof of concept, screenshots, or logs free of third-party personal data
In scope
- The Kuno recorder (firmware, Bluetooth pairing, recording LED)
- The Kuno companion app (iOS and Android)
- Our EU-hosted backend and transcription infrastructure
Out of scope
- Third-party services we don’t operate ourselves
- Social engineering against employees or physical access to offices
- Denial-of-service or load testing against production systems
Safe harbor for good-faith research
If you follow this policy, we treat your research as authorized. We will not pursue or support legal action against you, as long as you respect privacy, don’t destroy data, and don’t disrupt operations.
Legal notice: Test only with your own accounts and your own recordings. Listening to or recording other people’s conversations is a criminal offense under Section 201 of the German Criminal Code (StGB) and is not covered by the safe harbor. Never access third parties’ personal data (GDPR).
Our response
We confirm receipt of your report within 72 hours and keep you updated on progress. Please give us 90 days to address the issue before publishing any details. We’re happy to coordinate disclosure together with you.
Kuno does not run a public bug bounty program. That said, we’re glad to credit responsible reports in our acknowledgments if you’d like.