Security
Vulnerability disclosure policy
Sentinel is a security product, so we hold ourselves to the standard we monitor others against. If you believe you have found a vulnerability in Sentinel, we want to hear from you — and we will treat your report with respect.
How to report
Email security@9keys.io with a description of the issue, the steps to reproduce it, the URL or component affected, and any proof-of-concept detail you can safely share. This address is also published at /.well-known/security.txt per RFC 9116.
Please do not include another customer’s data in a report. If you encounter data that is not yours while testing, stop and report immediately.
Our commitments
- We aim to acknowledge reports within 2 business days and to give you an assessment within 5 business days. These are targets we hold ourselves to, not contractual guarantees.
- We will keep you informed of remediation progress on material findings.
- We will not take legal action against good-faith security research that follows this policy.
- With your permission, we will credit you once the issue is resolved.
In scope
- This web application (client portal, admin portal, and public pages)
- Sentinel check execution and reporting behavior
- Authentication, session, and authorization controls
Out of scope
- Denial-of-service or volumetric testing
- Social engineering, phishing, or physical attacks against 9Keys or its customers
- Scanning or testing customer assets monitored by Sentinel — they are not ours to authorize
- Automated scanner reports without a demonstrated security impact
Good-faith rules
- Only test against your own accounts and data.
- Do not access, modify, or delete data that is not yours.
- Do not degrade the service for others.
- Give us reasonable time to remediate before any public disclosure.
Live system status: /status · Policy last updated 2026-08-01