# Security Policy

Konto AI takes the security of our users' financial data seriously. This document describes how to report a vulnerability and what you can expect from us in return.

## Reporting a vulnerability

Please email **security@kontoai.com.br** with the details. If you prefer encryption, use the PGP key published at <https://kontoai.com.br/.well-known/security.txt>.

We commit to:

- Acknowledging receipt within **2 business days** (Brasília time, Mon-Fri).
- Providing an initial assessment and an estimated timeline within **5 business days**.
- Keeping you informed as we investigate and remediate.
- Crediting you in our public security advisories once the issue is fixed (if you wish — anonymous reports are equally welcome).

We ask in return:

- Give us a reasonable window to fix the issue before public disclosure — **90 days** is our default. We will agree on a shorter window for actively exploited issues.
- Do not access, modify, or delete data that does not belong to you. Stop testing and contact us immediately if you encounter another user's data during research.
- Do not perform denial-of-service testing, social engineering, or physical attacks against our staff or vendors.

## Scope

In scope for vulnerability reports:

- The Konto web application (`https://kontoai.com.br`, `https://www.kontoai.com.br`)
- The Konto Supabase Edge Functions (`https://upikhhwlkiwhqmyjrqfm.supabase.co/functions/v1/*`)
- Any subdomain of `kontoai.com.br`

Out of scope:

- Vulnerabilities in our third-party providers (Supabase, Netlify, Pluggy, Resend, Twilio, Mercado Pago, Anthropic, brapi.dev) — please report those directly to the vendor.
- Findings from automated scanners that have not been validated as exploitable.
- Reports of missing security headers without a demonstrated impact (we welcome these as suggestions, not vulnerabilities).
- Phishing pages hosted elsewhere.

## What we consider a vulnerability

The following always qualify:

- Authentication or authorization bypass that lets one user read, modify, or delete another user's data.
- Server-side code execution, SQL injection, or XSS in the application origin.
- Bypass of webhook signature verification (Mercado Pago, Twilio).
- Disclosure of secrets, service-role keys, or third-party API keys.
- Accidental publication of personal data of more than one user.

## Coordinated disclosure

We follow a 90-day coordinated disclosure model. After a fix ships, we publish a brief advisory describing the issue, the affected component, the fix, and credit (if applicable).

## Out-of-band channel

If for any reason `security@kontoai.com.br` is unavailable, contact the founder directly at `rafa@kontoai.com.br`.
