We build a platform that finds other people's vulnerabilities. We take reports about our own just as seriously.
Last updated: August 2026
If you believe you've found a security vulnerability in the Sakeon website, platform, or infrastructure, please report it to security@sakeon.com. Include as much detail as you can: the affected asset, steps to reproduce, and potential impact. Encrypted reports are welcome. We'll provide a PGP key on request.
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy while researching and reporting a vulnerability.
This policy covers sakeon.com and Sakeon-operated infrastructure. It does not cover vulnerabilities in a customer's own self-hosted deployment. Those should be reported to that customer's internal security team, or coordinated with Sakeon support if platform code is implicated.
A machine-readable version of this policy is published at /.well-known/security.txt, following RFC 9116.