SECURITY · DISCLOSURE
Vulnerability Disclosure
Report security issues safely and clearly. Good-faith research helps us protect Keisan and the teams that use it.
LAST UPDATED · JUNE 23, 2026
Overview
We welcome good-faith security research that helps protect Keisan users and the briefs and estimates they store with us. This policy explains what is in scope, how to report a finding, and what we ask researchers to avoid while testing.
Safe Harbor
If you follow this policy, make a good-faith effort to avoid privacy violations, and do not disrupt the Service, we will not initiate legal action against you for the research activity described in your report.
In Scope
- The public Keisan web application at keisan.jishulabs.com
- Authentication, authorization, and per-account isolation issues
- Exposure of secrets, customer briefs, or generated estimates
- Server-side request handling, API validation, and data access control issues
- Cross-site scripting, cross-site request forgery, and injection vulnerabilities
Out of Scope
- Denial-of-service testing, load testing, or resource exhaustion
- Social engineering, phishing, or physical attacks
- Reports based only on missing security headers without a practical exploit
- Automated scanner output without analysis or a reproducible impact path
- Issues in third-party services that do not affect Keisan directly
How to Report
Send reports to hello@jishulabs.com with a security-related subject, or through the contact page. Include enough detail for us to reproduce and triage the issue.
- Affected URL, endpoint, or feature
- Steps to reproduce, proof of concept, and expected impact
- Account email used for testing, if applicable
- Any logs, screenshots, or timestamps that help confirm the issue
Response Process
We aim to acknowledge valid reports within five business days, triage based on severity, and share meaningful updates as remediation progresses. Public disclosure should wait until we have validated and remediated the issue, unless we agree otherwise in writing.
Questions about this document? Get in touch.