> For the complete documentation index, see [llms.txt](https://docs.akiraghost.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.akiraghost.com/policies/security.md).

# Security & Responsible Disclosure

We take the security of Akira and our users seriously. If you've found a vulnerability, this page tells you how to report it and what you can expect from us in return.

*Last updated: June 19, 2026 · Version 1.0*

## How to report

Send your report to [**support@akiraghost.com**](mailto:support@akiraghost.com) with `Security` in the subject line, or open a private ticket in our [Discord server](https://akiraghost.com/discord) and tell staff you're reporting a security issue. We'll move the conversation somewhere private from there.

Include enough detail for us to reproduce the issue:

* What the vulnerability is and where you found it.
* Step-by-step instructions or a proof of concept.
* The impact you think it has.

## What's in scope

Security issues affecting our own systems are in scope:

* The Akira website and dashboard at [akiraghost.com](https://akiraghost.com).
* Official Akira software downloaded from our website.
* Our official utilities (whitelist, QuickFix, and similar tools we publish).

Some things are **out of scope**, and reports about them won't qualify:

* Third-party services we rely on (Stripe, PayPal, Discord, our CDN) — report those to the provider.
* Denial-of-service, spam, or volumetric attacks.
* Social engineering of our staff or users, and physical attacks.
* Findings from automated scanners with no demonstrated, working impact.

## Safe harbor

If you act in good faith and follow the rules below, we will **not** pursue or support legal action against you for your research, and we'll treat your report as authorized.

To stay covered:

* Only test against your own account and data — never another user's.
* Don't access, modify, or destroy data that isn't yours, and don't exfiltrate any data.
* Don't degrade or disrupt our services for other users.
* Give us a reasonable amount of time to fix the issue before you disclose it publicly.

If you're unsure whether something is allowed, ask us first.

## Recognition

We don't run a cash bounty program. For valid, good-faith reports we offer recognition instead — a thank-you and optional public credit, a role in our Discord, or digital goods we provide, at our discretion. The bigger and clearer the finding, the more we can do.

## What to expect from us

We aim to acknowledge security reports quickly — usually within the same window as our regular support, though complex reports can take longer to confirm. We'll keep you updated as we investigate and let you know when the issue is resolved.

{% hint style="info" %}
This is our disclosure process, not a warranty. For the legal terms covering your use of Akira, see the [Terms of Service](/policies/tos-term-of-service.md).
{% endhint %}
