Skip to content
Legal

Security & Vulnerability Disclosure

Last updated: July 25, 2026

At Kinetic Helix LLC(“Kinetic Helix”), we take the security of our systems, infrastructure, and user data seriously. We welcome responsible security researchers and community members who identify potential vulnerabilities and report them in good faith.

Safe harbor commitment

If you conduct security research in compliance with the principles and guidelines outlined on this page, we consider your research activities to be authorizedunder applicable anti-hacking laws (including the Computer Fraud and Abuse Act, 18 U.S.C. § 1030, and Florida computer crime statutes). We will not pursue legal action, initiate civil lawsuits, or request law enforcement investigations against researchers acting in good faith.

Guidelines & ground rules

To qualify for safe harbor protection, we ask that you adhere to the following standards:

  • Avoid data privacy violations: Do not access, download, view, or modify customer data or confidential information beyond what is strictly necessary to demonstrate a proof-of-concept.
  • Do not disrupt operations: Do not execute Denial of Service (DoS/DDoS) attacks, automated brute-force floods, resource exhaustion, or any action that degrades service performance for legitimate users.
  • No social engineering or physical attacks: Do not attempt phishing, pretexting, or social engineering attacks against Kinetic Helix employees, contractors, or customers, nor attempt physical access to facilities.
  • Coordinated disclosure: Allow us a reasonable opportunity (typically up to 90 days, or until a patch is deployed) to investigate and remediate reported issues before disclosing details publicly.
  • Lawful conduct: Comply with all applicable federal, state, and local laws during your testing.

Scope

In scope:

  • kinetichelix.io and its primary web applications and APIs operated directly by Kinetic Helix.
  • Proprietary application backend services and infrastructure owned and maintained by Kinetic Helix LLC.

Out of scope:

  • Third-party services, vendors, hosted infrastructure, or software-as-a-service providers we integrate with (e.g., Stripe, Supabase, Vercel, Resend).
  • Attacks targeting subdomains pointing to third-party services.
  • Clickjacking without demonstrable security impact or missing DNSSEC/SPF/DKIM/DMARC records without proven exploitation.

How to report a vulnerability

If you believe you have discovered a security vulnerability affecting our systems, please submit a detailed report to our security and legal team:

Kinetic Helix LLC

Attn: Security & Legal Compliance

Email: [email protected]

General Inquiries: [email protected]

Please include in your submission:

  1. A clear description and summary of the issue.
  2. Specific URLs, endpoints, or parameters affected.
  3. Step-by-step instructions or minimal proof-of-concept code to reliably reproduce the behavior.
  4. An assessment of potential real-world impact.

Our response commitment

When you submit a report adhering to these guidelines, we will:

  • Acknowledge receipt of your submission within two (2) business days.
  • Provide an initial assessment and timeline estimate for remediation.
  • Notify you once the vulnerability has been patched or resolved.
  • Publicly credit your ethical disclosure (if you desire public attribution).

For machine-readable security contact information, see our /.well-known/security.txt file according to RFC 9116. See also our Terms of Service and Privacy Policy.