Legal
Report a security vulnerability
Last updated: 7 September 2026
Scope
All products of the SaQura family (library SDKs, CertWatch, Crypto Inventory, Pass, Tresor, Messenger, Crypto API), the websites saqura.de, saqura.org and kyototech.co.jp, and the services we run for them. Manufacturer and operator is KyotoTech LLC, Kyoto, Japan.
How to reach us
Write to security@kyototech.co.jp. The machine-readable version of these details is at /.well-known/security.txt. Confidential details do not have to go into the first e-mail: after first contact we provide an encrypted channel on request.
What helps us
- Product and version (for websites, the address), operating system or platform.
- Steps to reproduce, ideally with a sample call or configuration.
- Your assessment of the impact and, if available, a proof of concept.
- How we can reach you, and whether you would like to be credited by name.
What you can expect from us
- Acknowledgement of receipt within three business days (Japan time).
- An initial assessment and a contact person for follow-up questions.
- Feedback as soon as a fix is available, or if we assess the report differently, with reasons.
- Credit in the release notes only with your consent.
We do not currently run a bounty programme. As a manufacturer we are subject to the EU Cyber Resilience Act (Regulation (EU) 2024/2847); we report actively exploited vulnerabilities to the competent authorities under Article 14 and inform affected users.
Coordinated disclosure
Please do not publish details before a fix is available, or at the latest 90 days after your report; we are happy to agree a different date with you. Researchers who act in good faith, limit themselves to what is necessary, do not access or alter third-party data, do not disrupt services and report the issue to us confidentially will not face legal action from us.
Not via this channel
Questions about licences, invoices or how to use a product go to support@kyototech.co.jp. Privacy requests are handled as described in our privacy policy.