KRY | LIVI · Vulnerability Disclosure

Kry Livi Vulnerability Disclosure

Vulnerability disclosure

KRY LIVI publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
CompanyHealthcareDigital HealthTelemedicineTelehealthPrimary CareMental HealthEuropeSwedenUnited Kingdom
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@kry.se

Source

Vulnerability Disclosure

kry-livi-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://www.kry.se/vulnerability-disclosure/
policy:
- https://www.kry.se/vulnerability-disclosure/
contact:
- security@kry.se
pgp:
  keyserver: https://keys.openpgp.org/
  lookup: search for security@kry.se
bug_bounty:
  offered: false
  note: 'Published statement: "We do not currently operate a reward-based bug bounty/disclosure
    program." Valid reporters may be publicly acknowledged with their permission.'
safe_harbor: true
safe_harbor_conditions:
- report in good faith
- avoid privacy violations and data destruction
- do not exploit beyond what is needed to demonstrate the issue
- do not access other people's data
scope:
  in_scope:
  - Kry mobile applications
  - Livi platforms
  - Web applications (kry.se, kry.no, livi.co.uk, livi.fr)
  - APIs
  - Integrated third-party services under Kry's control
  out_of_scope:
  - Social engineering
  - Physical attacks
  - Denial of service (DoS/DDoS)
  - Spam
  - Previously reported vulnerabilities
  - Third-party service vulnerabilities outside Kry's control
response_targets:
- stage: acknowledgement
  target: within 2 business days
- stage: validation
  target: within 15 business days
- stage: remediation
  target: per Kry's internal vulnerability management timeline (severity-based)
report_contents_requested:
- detailed description of the vulnerability and its potential impact
- steps to reproduce
- vulnerability type
- affected systems
- proof-of-concept evidence
- reporter contact details
evidence:
- source: https://www.kry.se/vulnerability-disclosure/
  kind: disclosure page
  keywords:
  - vulnerability
  - responsible disclosure
  - security research
  - bug bounty
  - security@
- source: https://www.kry.se/.well-known/security.txt
  kind: security.txt
  status: 404
  note: no RFC 9116 security.txt published; the policy is a web page only