Responsible Disclosure
Last updated: 27 August 2026
Report a vulnerability
Email security@knownstate.in with the affected asset, reproduction steps, and any proof-of-concept output. Machine-readable contact details are published at /.well-known/security.txt.
What we commit to
Acknowledgement within two business days, a triage decision within seven business days, and a status update at least every fourteen days until the report is closed. We will credit you publicly if you want that.
Scope
In scope: knownstate.in, its subdomains, and the SentinelIQ platform. Out of scope: client environments we monitor, third-party services we do not operate, and findings that require physical access or a compromised end-user device.
Please do not
Run denial-of-service or volumetric tests, access or modify data that is not yours, use social engineering against our staff, or publish details before we have confirmed a fix.
Safe harbour
Research conducted in good faith and within this policy will not lead to legal action from us. If a third party pursues action over work that followed this policy, we will state publicly that the research was authorised.