Vulnerability Disclosure Program
We build Komply to protect our clients’ most sensitive compliance data — and we know great security is a team effort. We welcome security researchers to responsibly test Komply and help us keep that data safe. Valid reports are recognized publicly and rewarded with a certificate.
Certificate of Appreciation
This is a recognition-based program — there is no cash bounty. Every valid, in-scope report earns an official Faseel Certificate of Appreciation (PDF) acknowledging your contribution.
Public Hall of Fame
Earn points for each valid finding and climb our public leaderboard. Your handle, points, and notable finding are showcased for the whole community to see.
Points & ranking
Points are awarded by validated severity. Your rank is your total points; ties are broken by who reported first.
| Severity | Points |
|---|---|
| Critical | 40 |
| High | 20 |
| Medium | 10 |
| Low | 5 |
| Informational | 1 |
Hall of Fame
Be the first
No researchers here yet. Submit the first valid report and claim the top spot on the Komply Hall of Fame.
In scope
- komply.faseel.app — the Komply web application
- The Komply API
Out of scope
- This marketing site (faseel.app)
- Third-party services (Vercel, DigitalOcean, Stripe, Google, etc.)
- Social engineering of staff or users
- Physical attacks against offices or hardware
- Denial of service (DoS/DDoS) and volumetric testing
- Automated scanner output with no validated, exploitable finding
Rules of engagement
- 1Stay strictly within the in-scope targets.
- 2Do not destroy, modify, or exfiltrate data. Access only what is necessary to prove a finding.
- 3Never violate the privacy of Komply users — use test accounts you create yourself.
- 4No denial of service, resource exhaustion, or spam.
- 5Report vulnerabilities promptly and give us reasonable time to remediate before any public disclosure.
- 6One vulnerability per report. If a chain requires multiple bugs, explain the chain clearly.
Qualifying
- Authentication / authorization bypass
- Insecure Direct Object Reference (IDOR)
- Server-Side Request Forgery (SSRF)
- Remote Code Execution (RCE)
- SQL / NoSQL injection
- Cross-Site Scripting (XSS) with real impact
- Privilege escalation
- Sensitive data exposure
Non-qualifying
- Missing best-practice headers with no demonstrated exploit
- Self-XSS
- Rate-limiting / brute-force issues with no further impact
- Outdated libraries with no working proof of concept
- Clickjacking on pages with no sensitive actions
- Reports generated solely by automated scanners
Submit a report
Fill in the form below and hit submit — it opens your email client with the full report pre-filled and addressed to us. Prefer to write it yourself? Email security@faseel.app. We acknowledge valid reports within 5 business days.
Safe harbor
We consider security research conducted in good faith and in accordance with this program to be authorized. We will not pursue or support legal action against researchers who follow these rules, stay in scope, avoid privacy violations and data destruction, and give us reasonable time to remediate before public disclosure. We will acknowledge your report within 5 business days. If in doubt about whether an action is permitted, ask us first at security@faseel.app.
About the Certificate of Appreciation
A Certificate of Appreciation (PDF) is issued to the researcher who submits the first valid report of each accepted vulnerability. Duplicate reports of an already-known issue are acknowledged but do not earn a separate certificate or points. Your points and Hall of Fame rank update once a report is validated by our team.