KaNun Advisory Book a briefing
Notices — Vulnerability disclosure with safe harbor

Security & Disclosure.

A security advisory practice should hold itself to the standard it recommends. This page describes how this site is built and how to report a vulnerability to us.

How this site is secured

kanunadvisory.com is a static site — no accounts, no databases, no server-side code paths beyond form handling by our host. All traffic is TLS-encrypted with HSTS. Response headers enforce content-type integrity, frame denial, and a strict referrer policy. We collect the minimum data described in our Privacy Policy, set no cookies, and run no third-party trackers. The deployment pipeline is version-controlled with signed-off changes.

Vulnerability disclosure policy

We welcome good-faith security research on kanunadvisory.com and will not pursue or support legal action against researchers who follow this policy (safe harbor).

Scope. kanunadvisory.com and its subdomains. Out of scope: denial of service, volumetric attacks, social engineering of the principal, physical attacks, and third-party services we use (report Netlify issues to Netlify, etc.).

How to report. Email security@kanunadvisory.com with steps to reproduce, impact, and any proof-of-concept. Machine-readable details are published at /.well-known/security.txt (RFC 9116).

What to expect. Acknowledgment within two business days; a substantive assessment within ten; a fix or a reasoned decision as fast as severity warrants. We do not operate a paid bounty, but with your permission we credit meaningful findings here.

Ground rules. Do not access, modify, or exfiltrate data that is not yours; do not degrade the service; give us reasonable time to remediate before public disclosure (we ask 90 days, and we will move faster than that).

Questions about our practices

Prospective clients performing vendor diligence on the practice itself may request our engagement-security summary — data handling, confidentiality, tooling, and insurance — at munya@kanunadvisory.com.