Security

Vulnerability disclosure policy

Sentinel is a security product, so we hold ourselves to the standard we monitor others against. If you believe you have found a vulnerability in Sentinel, we want to hear from you — and we will treat your report with respect.

How to report

Email security@9keys.io with a description of the issue, the steps to reproduce it, the URL or component affected, and any proof-of-concept detail you can safely share. This address is also published at /.well-known/security.txt per RFC 9116.

Please do not include another customer’s data in a report. If you encounter data that is not yours while testing, stop and report immediately.

Our commitments

  • We aim to acknowledge reports within 2 business days and to give you an assessment within 5 business days. These are targets we hold ourselves to, not contractual guarantees.
  • We will keep you informed of remediation progress on material findings.
  • We will not take legal action against good-faith security research that follows this policy.
  • With your permission, we will credit you once the issue is resolved.

In scope

  • This web application (client portal, admin portal, and public pages)
  • Sentinel check execution and reporting behavior
  • Authentication, session, and authorization controls

Out of scope

  • Denial-of-service or volumetric testing
  • Social engineering, phishing, or physical attacks against 9Keys or its customers
  • Scanning or testing customer assets monitored by Sentinel — they are not ours to authorize
  • Automated scanner reports without a demonstrated security impact

Good-faith rules

  • Only test against your own accounts and data.
  • Do not access, modify, or delete data that is not yours.
  • Do not degrade the service for others.
  • Give us reasonable time to remediate before any public disclosure.

Live system status: /status · Policy last updated 2026-08-01