Report a Vulnerability
If you have found a security or privacy flaw in Keystody, please tell us privately first. This page explains what is in scope, how to report, and what happens next.
Last updated: 20 August 2026
1. How to report
Email security@keystody.com. This mailbox is monitored and is separate from product support, so a security report cannot be lost in ordinary triage.
Never send us a seed phrase, a private key, or another person’s data. We do not need them to reproduce a bug, and we do not want them. If a report cannot be demonstrated without one, describe the steps instead and we will work it out with you.
2. What is in scope
Our production systems:
- keystody.com — this marketing site
- app.keystody.com — the application
- api.keystody.com — the API
Explicitly out of scope:
- dev.keystody.com and app.dev.keystody.com — pre-production and testnet sandbox environments. They are deliberately reachable and deliberately incomplete; findings there are usually not findings.
- mail.keystody.com — operated by our email host, not by us. Report issues there to the provider.
- Third-party services we use but do not control. Please report those to the service concerned.
3. Rules for testing
Please test only against your own account and your own funds, and use our testnet sandbox rather than mainnet wherever you can — it exists precisely so nothing you do costs anyone real Bitcoin. Specifically, do not:
- access, modify or retain another person’s data
- run denial-of-service or resource-exhaustion tests
- social-engineer or phish our staff or our customers
- attempt physical access to our premises or hardware
- destroy or alter data that is not yours
- run high-volume automated scanning without arranging it with us first
- move, or attempt to move, Bitcoin that does not belong to you
If you encounter personal data during testing, stop, do not save it, and tell us what you found.
4. Our commitment to you
If you follow the rules above and report in good faith, we will not pursue or support legal action against you for your research. We consider it authorised, and we will say so if a third party suggests otherwise.
If a third party brings legal action against you for research that followed this policy, we will make it known that your actions were authorised.
This is not a waiver of anyone else’s rights, and it does not authorise you to act against systems that are not ours.
5. What to include
A report we can act on usually has:
- the affected URL or component
- what kind of issue it is
- steps to reproduce it
- what you expected to happen, and what happened instead
- why it matters — what an attacker could do
- any request or response data that helps, with secrets and personal data removed
- how to contact you
- whether you intend to publish, and roughly when
6. What happens next
What to expect:
- Acknowledgement within 3 business days. A human reply, not an autoresponder.
- Initial assessment within 7 business days — whether we can reproduce it, and how serious we think it is.
- Continued updates while we work on anything we have confirmed.
We will not commit to a fix date before we understand the problem. Once we do, we will tell you what we are doing and roughly when.
Please give us a reasonable opportunity to fix an issue before publishing it. We are happy to coordinate timing with you, and to credit you when we disclose — or to leave you out of it, if you prefer.
7. Credit, not cash
We do not currently offer payment for reports. We do appreciate responsible disclosure, and we will credit you publicly if you would like that.
8. Not a security issue?
If it is an ordinary bug — a broken button, a confusing screen, an onboarding step that fails — please use support@keystody.com instead. It will reach us faster that way.
For how Keystody actually works and what it can and cannot do, see Security & Trust.