Security Policy
DuoKey welcomes responsible vulnerability reports from security researchers.
We do not currently operate a public bug bounty program and we do not offer monetary rewards for vulnerability reports. Submitting a report does not create any entitlement to compensation.
The presence of this policy or our security.txt file does not grant permission to perform intrusive testing, denial-of-service testing, social engineering, physical attacks, or testing against third-party systems.
Please report suspected vulnerabilities to security@duokey.com with enough detail to allow us to reproduce and assess the issue.