1. Overview

Keboola is committed to protecting our customers, employees, and partners. We welcome the contributions of the security-research community and provide a clear, safe-harbor process for reporting vulnerabilities.

2. Safe-Harbor Statement

If you follow all guidelines in this document when researching and reporting, Keboola will:

3. How to Report

Submit all vulnerability reports by email to security@keboola.com. All reports, communication, and reward processing are handled over email unless otherwise agreed.

4. In-Scope Targets

The following production domains (and their sub-domains) are in scope:

Cloud Region Base URL
Azure North Europe https://connection.north-europe.azure.keboola.com
AWS us-east-1 https://connection.keboola.com
AWS eu-central-1 https://connection.eu-central-1.keboola.com
GCP europe-west3 https://connection.europe-west3.gcp.keboola.com
GCP us-east4 https://connection.us-east4.gcp.keboola.com

Note: These endpoints expose one logical service; exploiting the same bug on multiple regions counts as one report.

Test Accounts: Keboola does not provide dedicated test environments or accounts. Researchers must use only their own data and accounts for testing. Access to other customers' data or Keboola internal data is strictly prohibited.

5. Out-of-Scope Findings

The categories below do not qualify for a reward and may be closed as informational:

6. Allowed Research Activities

You may:

7. Prohibited Activities

8. Report Quality & Reproducibility

Your report must include:

Important: Access to other customers' data or Keboola internal systems during testing is strictly prohibited. Your PoC must demonstrate the vulnerability using only resources you legitimately own and control.

Unclear or partial reports may be closed or returned for more information and may affect bounty eligibility.

9. Severity Classification & Rewards

Reward amounts are determined based on severity, impact, and report quality. Keboola reserves sole discretion over all reward decisions and severity classifications.

Severity Levels & Reward Ranges

Severity Reward Range Examples
Critical Up to $500 • Remote Code Execution (RCE) • SQL Injection with access to all customer data • Authentication bypass affecting all users • Server-Side Request Forgery (SSRF) leading to cloud metadata access
High Up to $300 • Authentication bypass for individual accounts • Insecure Direct Object Reference (IDOR) exposing sensitive customer data • Stored XSS in privileged contexts • Privilege escalation from user to admin
Medium Up to $150 • Reflected XSS in non-privileged contexts • IDOR exposing non-sensitive data • CSRF on state-changing operations • Information disclosure of technical details that could aid further attacks
Low Up to $50 • Minor CSRF on non-critical operations • Open redirects without demonstrated security impact • Weak password policies • Rate limiting issues without DoS impact
Informational No reward • Out-of-scope findings (see Section 5) • Issues without security impact • Best-practice recommendations

Additional Rules

10. Appeal Process

If you disagree with the severity assessment or report closure decision:

  1. Reply to the report email thread with a detailed explanation of why you believe the assessment should be reconsidered.
  2. Provide additional evidence or technical details that support your position.
  3. Our security team will review your appeal within 30 business days.
  4. The appeal decision is final and at Keboola's sole discretion.

Please note: Appeals should be substantive and technical in nature. Repeated appeals on the same decision without new information may be considered spam.

11. Coordinated Disclosure

Keboola follows responsible disclosure principles:

12. Communication Guidelines & Prohibited Behavior

To maintain an efficient and respectful disclosure process:

Acceptable:

Prohibited (will result in permanent ban):

Violation of communication guidelines or program rules will result in immediate and permanent ban from the program, forfeiture of any pending rewards, and potential legal action if applicable.

13. Our Commitment to You

14. Report Rejection Policy

Keboola reserves the right to close reports without notice or response if they:

This policy exists to maintain program efficiency and focus security team resources on valid, actionable reports.


Contact: security@keboola.com — for vulnerability reports and program questions.