Komply Security

Vulnerability Disclosure Program

We build Komply to protect our clients’ most sensitive compliance data — and we know great security is a team effort. We welcome security researchers to responsibly test Komply and help us keep that data safe. Valid reports are recognized publicly and rewarded with a certificate.

Certificate of Appreciation

This is a recognition-based program — there is no cash bounty. Every valid, in-scope report earns an official Faseel Certificate of Appreciation (PDF) acknowledging your contribution.

Public Hall of Fame

Earn points for each valid finding and climb our public leaderboard. Your handle, points, and notable finding are showcased for the whole community to see.

Points & ranking

Points are awarded by validated severity. Your rank is your total points; ties are broken by who reported first.

SeverityPoints
Critical40
High20
Medium10
Low5
Informational1

Hall of Fame

Be the first

No researchers here yet. Submit the first valid report and claim the top spot on the Komply Hall of Fame.

In scope

  • komply.faseel.app — the Komply web application
  • The Komply API

Out of scope

  • This marketing site (faseel.app)
  • Third-party services (Vercel, DigitalOcean, Stripe, Google, etc.)
  • Social engineering of staff or users
  • Physical attacks against offices or hardware
  • Denial of service (DoS/DDoS) and volumetric testing
  • Automated scanner output with no validated, exploitable finding

Rules of engagement

  • 1Stay strictly within the in-scope targets.
  • 2Do not destroy, modify, or exfiltrate data. Access only what is necessary to prove a finding.
  • 3Never violate the privacy of Komply users — use test accounts you create yourself.
  • 4No denial of service, resource exhaustion, or spam.
  • 5Report vulnerabilities promptly and give us reasonable time to remediate before any public disclosure.
  • 6One vulnerability per report. If a chain requires multiple bugs, explain the chain clearly.

Qualifying

  • Authentication / authorization bypass
  • Insecure Direct Object Reference (IDOR)
  • Server-Side Request Forgery (SSRF)
  • Remote Code Execution (RCE)
  • SQL / NoSQL injection
  • Cross-Site Scripting (XSS) with real impact
  • Privilege escalation
  • Sensitive data exposure

Non-qualifying

  • Missing best-practice headers with no demonstrated exploit
  • Self-XSS
  • Rate-limiting / brute-force issues with no further impact
  • Outdated libraries with no working proof of concept
  • Clickjacking on pages with no sensitive actions
  • Reports generated solely by automated scanners

Submit a report

Fill in the form below and hit submit — it opens your email client with the full report pre-filled and addressed to us. Prefer to write it yourself? Email security@faseel.app. We acknowledge valid reports within 5 business days.

Safe harbor

We consider security research conducted in good faith and in accordance with this program to be authorized. We will not pursue or support legal action against researchers who follow these rules, stay in scope, avoid privacy violations and data destruction, and give us reasonable time to remediate before public disclosure. We will acknowledge your report within 5 business days. If in doubt about whether an action is permitted, ask us first at security@faseel.app.

About the Certificate of Appreciation

A Certificate of Appreciation (PDF) is issued to the researcher who submits the first valid report of each accepted vulnerability. Duplicate reports of an already-known issue are acknowledged but do not earn a separate certificate or points. Your points and Hall of Fame rank update once a report is validated by our team.