Security Contact

Security and Responsible Disclosure

If you discover a potential security issue, report it directly to our team.

Responsible Disclosure Process

If you discover a security issue, please report it privately. Include a clear summary, affected endpoint or flow, reproduction steps, and risk assessment.

  • Email: support@juveniq.co.za
  • Use subject line: Security Report - Kota-OS
  • Include impact, steps to reproduce, and supporting evidence

Safe Harbor Expectations

We support good-faith security research. If you act responsibly, avoid privacy violations, and refrain from service disruption, we will treat your report as authorized security testing within this policy scope.

Out-of-Scope and Prohibited Testing

  • No denial-of-service or brute-force attacks
  • No social engineering, phishing, or physical intrusion attempts
  • No unauthorized access to third-party systems
  • No data exfiltration beyond what is necessary to demonstrate the issue

Response Targets

  • Acknowledgement target: within 1 business day
  • Triage target: within 3 business days
  • Resolution timing depends on severity and complexity
  • Critical vulnerabilities are prioritized immediately

Severity and Remediation Flow

Reported issues are evaluated by impact, exploitability, and affected data scope. Confirmed vulnerabilities enter prioritized remediation workflows with verification before closure.

Legal and Company Disclosure

  • Responsible Party: JuveniQ (trading as Kota-OS)
  • Company Registration Number: K2025/699085/07
  • Phone: +27 607431268
  • Phone (Backup): +27 783322419
  • Location: Gauteng, Johannesburg

For privacy rights and data handling details, refer to our Privacy Policy and Terms of Service.