Kraken Technologies · Vulnerability Disclosure

Kraken Technologies Vulnerability Disclosure

Vulnerability disclosure

Kraken Technologies runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

EnergyUnited KingdomUtilitiesElectricityGasSmart MeteringDemand ResponseDERBillingEnergy Platform
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
{"type" => "form", "value" => "Submission Form linked from https://www.kraken.tech/vulnerability-disclosure-process (\"Report a vulnerability\")"}

Source

Vulnerability Disclosure

kraken-technologies-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://www.kraken.tech/vulnerability-disclosure-process
url: https://www.kraken.tech/vulnerability-disclosure-process
summary: >-
  Kraken Technologies runs a published Vulnerability Disclosure Process, explicitly separate from a
  private HackerOne program. Reports go through a submission form, not an email address; there is no
  bounty. Kraken commits to a 2-business-day first response and 2-business-day triage target. The
  automated probe missed this page because it sits at a non-standard path
  (/vulnerability-disclosure-process, not /security or /responsible-disclosure) and because
  kraken.tech serves no /.well-known/security.txt.
policy:
- https://www.kraken.tech/vulnerability-disclosure-process
contact:
- type: form
  value: 'Submission Form linked from https://www.kraken.tech/vulnerability-disclosure-process ("Report a vulnerability")'
bounty:
  offered: false
  verbatim: 'Please note we do not offer monetary rewards for vulnerability disclosures.'
private_program:
  platform: HackerOne
  public: false
  verbatim: 'Our Vulnerability Disclosure process is separate to our Private HackerOne program.'
response_targets:
  first_response: 2 business days
  triage: 2 business days
  verbatim: >-
    "Kraken will make a best effort to meet the following response time targets for vulnerability
    report submissions: Time to first response (from reporting) = 2 business days; Time to triage
    (from reporting) = 2 business days."
scope:
  in_scope:
  - Security vulnerabilities identified in any internet-facing service owned, operated, or controlled by Kraken.
  out_of_scope:
  - Rate limiting issues on Kraken's demo form
  - Clickjacking on pages with no sensitive actions
  - Unauthenticated/logout/login CSRF
  - Attacks requiring MITM or physical access to a user's device
  - Previously known vulnerable libraries without a working proof of concept
  - CSV injection without demonstrating a vulnerability
  - Missing best practices in SSL/TLS configuration
  - Any activity that could lead to disruption of service (DoS)
  - Content spoofing and text injection without an attack vector or HTML/CSS modification
rules:
- Provide detailed reports with reproducible steps.
- Submit one vulnerability per report, unless chaining is needed to show impact.
- Social engineering (phishing, vishing, smishing) is prohibited.
- Make a good-faith effort to avoid privacy violations, data destruction, and service interruption; only interact with accounts you own or have explicit permission for.
security_txt:
  present: false
  probes:
  - {url: 'https://www.kraken.tech/.well-known/security.txt', status: 404}
  - {url: 'https://kraken.tech/.well-known/security.txt', status: 404}
  - {url: 'https://docs.kraken.tech/.well-known/security.txt', status: 200, note: 'SSO login page (text/html), not RFC 9116'}
  gap: >-
    Kraken has a real disclosure process but no RFC 9116 security.txt pointing at it — a one-line
    fix that would make the policy machine-discoverable.
related_contacts:
  data_protection_officer: dpo@kraken.tech
  privacy: privacy@kraken.tech
evidence:
- {source: 'https://www.kraken.tech/vulnerability-disclosure-process', kind: disclosure-policy, status: 200, date: '2026-07-27'}
- {source: 'https://www.kraken.tech/legal/trust-center', kind: security-program, status: 200, date: '2026-07-27'}