Security

Reporting a vulnerability

Email support@usekeel.io with “Security” in the subject line. Include what you found, the steps to reproduce it, and the affected URLs or accounts.

We review every report and will follow up with you. Please give us reasonable time to fix the issue before disclosing it publicly.

Good-faith research

Only test against your own account. Do not access other users’ data, disrupt the service, or run automated high-volume scans. We will not pursue good-faith research that follows these rules. We don’t run a paid bug bounty.

About Keel

Keel is non-custodial and never holds user funds. AI assistants sign in to Keel with OAuth using short-lived access tokens.

Machine-readable contact details: /.well-known/security.txt.