Incident response andbreach notification.
How to report a security issue to Kenii, what happens next, and how quickly every affected institution hears about it.
What counts as an incident
- A security defect in shipped Kenii software.
- Unauthorized access to a Kenii vendor-side service.
- Loss or exposure of a credential held by Kenii, including one issued by an institution.
- Any report from an institution, a researcher or a member of the public alleging one of the above.
Reporting an incident to Kenii
Write to security@kenii.app, or use the direct contact named in your agreement. Kenii acknowledges a report within one business day.
A reporter acting in good faith is not pursued for reporting a defect.
The steps
- Acknowledge and record. Log the time received, the reporter, and what was claimed.
- Assess. Determine whether the report is valid, what it reaches, and which institutions are affected. Assign a severity.
- Contain. Revoke exposed credentials, disable the affected function, or take a vendor-side service offline. Containment takes priority over root cause.
- Notify. See the table below.
- Remediate. Fix the defect, validate the fix against the automated suites, release it, and tell institutions what to apply.
- Review. Within ten business days of closure, record what happened, what was fixed, and what changes so it does not recur.
Notification
Kenii notifies every institution running an affected version, not only the one that reported it.
| Severity | Definition | Notify within |
|---|---|---|
| Critical | Unauthenticated access to institutional data, or remote code execution | 24 hours of confirmation |
| High | Authenticated privilege escalation, or exposure of a credential | 3 business days |
| Moderate | A defect requiring unusual conditions, with limited reach | With the next release |
Kenii will not delay notification to finish a fix. A notification states what was found, what it reaches, what an institution must do, and when a fix is available.
Legal obligations
Kenii complies with applicable breach notification law and with notification terms in the institutional agreement, whichever requires action sooner. Where an institution must notify individuals, Kenii supplies the facts that institution needs.
The limit worth stating
Because institutional data resides on institutional infrastructure, most breach scenarios in a Kenii deployment are breaches of the institution’s environment, which Kenii cannot detect and does not monitor.
This document covers what Kenii can see: its own services, its own code, and its own credentials. Detection inside the institution’s environment remains the institution’s.
Report somethingto security@kenii.app.
Acknowledged within one business day. Good-faith reporters are never pursued.