diff --git a/security-vulnerability-reporting.mdx b/security-vulnerability-reporting.mdx index 9fed9839..13101b79 100644 --- a/security-vulnerability-reporting.mdx +++ b/security-vulnerability-reporting.mdx @@ -1,12 +1,346 @@ --- -title: "Vulnerability Disclosure" -description: "Report a security vulnerability to Kernel through our HackerOne-powered disclosure program" +title: "Bug Bounty Program: Scope and Policy" +description: "Kernel's bug bounty scope, rewards, severity assessment, safe harbor, and rules of engagement" --- -Kernel takes the security of our systems and customer data seriously. We welcome and appreciate responsible disclosure of security vulnerabilities from the security research community. +{/* This page is a verbatim copy of Kernel's internal bug bounty scope and policy document, + which is the single source of truth. Do not edit the policy text here. Change the source + document and re-copy. The only changes permitted in this file are the frontmatter above, + the embedded HackerOne submission form in section 2 (collapsed in an Accordion so it + does not push the rest of the policy below the fold), and escaping every literal dollar + sign as \$ so Mintlify does not parse paired $...$ as LaTeX math. */} -If you believe you have found a security vulnerability in any Kernel-owned system, please submit your report using the form below. Our security team will triage and respond to all valid submissions. +## At a glance -For questions about our vulnerability disclosure program, contact [security@kernel.sh](mailto:security@kernel.sh). If you prefer to report via email, you can send your submission directly to [hackerone@kernel.sh](mailto:hackerone@kernel.sh). +| | | +|---|---| +| Program type | Private, invite only bug bounty | +| Rewards | \$50 to \$2,500, plus discretionary bonuses (§3) | +| Severity framework | CVSS v3.1, assessed against Kernel's trust boundaries (§8) | +| First response | 3 business days, from a human (§9) | +| Payment | Within 14 business days of triage (§9) | +| Safe harbor | HackerOne Gold Standard Safe Harbor (§10) | +| Disclosure | You may publish; we ask you to wait for the fix (§11) | +| Contact | `security@kernel.sh` | -