If you think you found a security problem, thank you. Please tell us privately before you publish it.
How
Email team@keplar.one with:
- What you found and where (URL, feature).
- Steps to reproduce, or a proof of concept that does the least harm needed to show it.
- What you think the impact is.
- How to contact you.
Keplar publishes this contact in a standard security.txt file, so automated tools can find it.
Please do not
- Access, change or delete other people's data.
- Run denial-of-service tests or high-volume scans.
- Use social engineering against anyone.
- Test against paid models in a way that creates cost.
What to expect
A reply to confirm receipt. Keplar does not publish a fixed response time or a bounty program on this page; if either is added, it will be stated in these docs with a date.
Out of scope
Reports that only say a header is missing without a demonstrated impact, issues in third-party services (report to the vendor), and model answers that are wrong. A wrong or biased answer is a quality issue; use the feedback form.
If you see KeplarBot in your logs
KeplarBot is the user agent Keplar uses when someone imports a product page into Create. It is not a search crawler: it opens one product page and a few images per import, reads robots.txt first and obeys it. The page at /bot explains what it does and how to block it with a robots.txt rule. If you think it is misbehaving, or want a page removed from someone's import, write to team@keplar.one with the URL and the time you saw it.
Related
- Account security: How sign-in sessions work, how to review and end sessions, what to do if you lose email access, and practical habits that protect your account.
- Connected app security: How Keplar defends against server-side request forgery, prompt injection through tool output, secret leaks and silent tool changes when you connect MCP servers.