Coordinated vulnerability disclosure

Report a vulnerability

If you have found a vulnerability in Kunnus or on this website, please report it to us. Every report is treated confidentially.

Formal policy in preparation

A formally documented coordinated disclosure policy is not yet available. We are drafting it and will publish it on this page as soon as it is in place. Until then, the process described below applies.

How a report is handled

  1. 01

    You submit the report

    The portal asks for a title and a description, optionally your own severity assessment and the affected website. Contact details are optional, though without them we cannot get back to you.

  2. 02

    We assess it and get back to you

    Your report lands directly with our security team, which reproduces the finding and assesses its severity. If you leave contact details, we confirm receipt of your report and keep you posted on its status.

  3. 03

    We fix it and publish an advisory

    Once a fix is available, we coordinate the timing of publication with you. The advisory goes out as a machine-readable document, and we name you as the reporter if you would like that.

Published advisories

We publish our advisories in CSAF, the machine-readable format for security advisories, and list them in a ROLIE feed. Your vulnerability management can subscribe to that feed instead of waiting for someone to read a web page.

Reporting address, this policy and the advisory feed are also machine-readable at the well-known location.

Frequently asked questions

Where do I report a vulnerability in a Kunnus product?
Through our disclosure portal at app.kunnus.tech/disclose/think-ahead-tech. It goes straight to our security team. Alternatively you can write to security@think-ahead.tech. The same addresses are listed in our security.txt at kunnus.tech/.well-known/security.txt.
What happens after I submit a report?
Our security team reproduces the finding and assesses its severity. If you leave contact details, we confirm receipt and keep you posted while we work on a fix, and we agree the timing of publication with you before we publish an advisory.
Where can I find published security advisories?
In our CSAF feed at app.kunnus.tech/csaf/think-ahead-tech/white/feed.json. CSAF is the machine-readable standard for security advisories, so vulnerability management tools can consume the feed automatically.
Does this also cover the open-source Kunnus Scanner?
Yes. The scanner, its container images, the Kunnus platform and this website are all in scope.
Powered byKunnusSee the reporting module in Kunnus

Last updated: 19 August 2026