From f87c050ef615c8be0c74d68825024a8c21f96ff7 Mon Sep 17 00:00:00 2001 From: Ulzii Otgonbaatar Date: Thu, 27 Aug 2026 08:56:14 -0600 Subject: [PATCH 1/4] Publish bug bounty scope and policy Replaces the bare HackerOne embed on /security-vulnerability-reporting with the full program policy: scope tiers, reward table, the isolation boundary rules in section 5, rules of engagement, severity methodology, response and remediation commitments, Gold Standard Safe Harbor, and disclosure terms. The page body is a verbatim copy of the internal bug bounty scope and policy document, which stays the single source of truth. The only changes are the frontmatter, the embedded submission form in section 2, and escaping literal dollar signs so Mintlify does not parse paired $...$ as LaTeX math. Section 10's safe harbor text is byte identical to HackerOne's Gold Standard wording, which is what earns the badge. Also points security.mdx 2.3 at the policy instead of restating reward amounts and SLAs, so those cannot drift, and swaps the embed to the current HackerOne program. Co-Authored-By: Claude Opus 5 (1M context) --- security-vulnerability-reporting.mdx | 336 ++++++++++++++++++++++++++- security.mdx | 10 +- 2 files changed, 337 insertions(+), 9 deletions(-) diff --git a/security-vulnerability-reporting.mdx b/security-vulnerability-reporting.mdx index 9fed9839..f20ff0d5 100644 --- a/security-vulnerability-reporting.mdx +++ b/security-vulnerability-reporting.mdx @@ -1,12 +1,336 @@ --- -title: "Vulnerability Disclosure" -description: "Report a security vulnerability to Kernel through our HackerOne-powered disclosure program" +title: "Bug Bounty Program: Scope and Policy" +description: "Kernel's bug bounty scope, rewards, severity assessment, safe harbor, and rules of engagement" --- -Kernel takes the security of our systems and customer data seriously. We welcome and appreciate responsible disclosure of security vulnerabilities from the security research community. +{/* This page is a verbatim copy of Kernel's internal bug bounty scope and policy document, + which is the single source of truth. Do not edit the policy text here. Change the source + document and re-copy. The only changes permitted in this file are the frontmatter above, + the embedded HackerOne submission form in section 2, and escaping every literal dollar + sign as \$ so Mintlify does not parse paired $...$ as LaTeX math. */} -If you believe you have found a security vulnerability in any Kernel-owned system, please submit your report using the form below. Our security team will triage and respond to all valid submissions. +## At a glance -For questions about our vulnerability disclosure program, contact [security@kernel.sh](mailto:security@kernel.sh). If you prefer to report via email, you can send your submission directly to [hackerone@kernel.sh](mailto:hackerone@kernel.sh). +| | | +|---|---| +| Program type | Private, invite only bug bounty | +| Rewards | \$50 to \$2,500, plus discretionary bonuses (§3) | +| Severity framework | CVSS v3.1, assessed against Kernel's trust boundaries (§8) | +| First response | 3 business days, from a human (§9) | +| Payment | Within 14 business days of triage (§9) | +| Safe harbor | HackerOne Gold Standard Safe Harbor (§10) | +| Disclosure | You may publish; we ask you to wait for the fix (§11) | +| Contact | `security@kernel.sh` | + +**Before you start testing, read §5.** Kernel sells browsers running in microVMs where you have root by design. That makes the line between what is in scope and what is not unusual for our product, and §5 is where we draw it precisely. Most invalid reports we receive are reports of intended behavior. + +*** + +## 1. Our commitments + +Kernel runs cloud browser infrastructure. Our customers trust us to keep their sessions, credentials, and data isolated from every other tenant, so we take that boundary seriously and we want to hear from you when it does not hold. + +When working with us under this policy, you can expect us to: + +* Respond to your report promptly, and work with you to understand and validate it +* Keep you informed about the progress of a vulnerability as it is processed +* Work to remediate discovered vulnerabilities in a timely manner, within our operational constraints +* Recognize your contribution if you are the first to report a unique vulnerability and your report triggers a code or configuration change +* Extend safe harbor for vulnerability research related to this policy + +You will receive a response confirming receipt of your report, written by a person rather than generated automatically, plus timely updates through remediation. You may request an update at any time. If we are going to miss one of the targets in §9 we will tell you before we miss it and give you a new date. + +## 2. How to report + +Submit through our HackerOne program. Keep all report information on HackerOne. Please do not post it to video sharing or paste sites. + +