KRY · Vulnerability Disclosure

Kry Vulnerability Disclosure

Vulnerability disclosure

KRY runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyConsumerHealthcareDigital HealthTelemedicinePrimary CareMental HealthSwedenEurope
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@kry.se

Source

Vulnerability Disclosure

kry-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://www.kry.se/vulnerability-disclosure/
policy:
- https://www.kry.se/vulnerability-disclosure/
contact:
- security@kry.se
encryption:
  pgp: true
  key_source: https://keys.openpgp.org/
  note: PGP-encrypted submissions accepted at the same address; the public key is
    retrieved from keys.openpgp.org
bug_bounty:
  offered: false
  platform: null
  note: 'Stated on the policy page: Kry does not currently operate a reward-based bug
    bounty/disclosure program. No HackerOne, Bugcrowd or Intigriti program is named.'
recognition: Researchers may be publicly recognised, with their permission, after a
  report is resolved.
scope:
  in_scope:
  - Kry mobile applications (iOS and Android)
  - Livi mobile and web platforms
  - Web applications at kry.se, kry.no, livi.co.uk, livi.fr
  - APIs and backend infrastructure
  - Third-party services where Kry maintains control
  out_of_scope:
  - Social engineering and phishing
  - Physical attacks
  - Denial of Service
  - Previously reported vulnerabilities
  - Issues requiring unlikely user interaction
response_commitments:
  acknowledgement: within 2 business days
  validation: within 15 business days
  status_updates: at least every 10 business days
  note: Kry states timelines may adjust based on complexity and resource availability.
well_known_security_txt:
  published: false
  note: /.well-known/security.txt returns 404 on both www.kry.se and kry.se; the disclosure
    policy is published as an HTML page only.
evidence:
- source: https://www.kry.se/vulnerability-disclosure/
  kind: disclosure page
  keywords:
  - vulnerability
  - responsible disclosure
  - security research
  - bug bounty
  - security@