Kensora logoKensora logo Project Kensora
Private reporting is open now.

Security and safety reporting

Kensora handles sensitive mental-health information, and it ships safety features that show support resources when someone's words are the kind a person in danger might use. A weakness in either one matters here, and both get the same private front door.

If you are in crisis yourself, please stop reading this page and contact your local emergency number or find a helpline at findahelpline.com. A report can wait. You matter more.

What to report privately, never in public

Some findings are unsafe to describe in public, now or once the repository and its issue tracker open, either because they expose people before a fix exists or because the reproduction itself contains wording that should not sit in an open space. Please send both kinds below through the private route.

Security vulnerabilities

Anything that could expose user information, weaken encryption, or compromise someone's device or account. The familiar territory of a security report.

Safety weaknesses

Cases where wording a person in danger might use does not cause Kensora to show support resources. An evasion of the layer of behavior that is meant to show support resources once that kind of wording appears. A wrong or dead helpline number anywhere in the app.

These reports are as valuable to this project as any CVE, and they often cannot be written safely in public, because reproducing them means writing out the very wording that does not belong in an open space. The private route exists so you can still tell us.

Kensora is not a crisis service, and it does not detect or prevent any medical or mental-health condition or emergency. A report about the safety features is a report about software behavior, never a judgment about any person.

How to report

Email security@kensora.io. This is the published security contact for Kensora, and it works today. When the public repository opens, GitHub private vulnerability reporting will be added alongside it, and both routes will reach the same people.

In your report, please include:

For safety reports

A content warning at the top of your message is appreciated. Include the language and the exact phrasing that produced the behavior, since precision is what makes the report fixable. Please never include a real person's information or anyone's personal crisis history.

What to expect

Honesty over promises. This is a small project, and reports are read by people rather than a triage system, so this page does not pledge a response window it might not keep. Here is what it does pledge:

Scope

If you are not sure whether something fits, send it anyway. The worst case is that it is out of scope.