Incident response andbreach notification.

How to report a security issue to Kenii, what happens next, and how quickly every affected institution hears about it.

Owner
Tony Shaw, Co-Founder. Deputy: David Springer, Co-Founder
Review cycle
Annually, and after every incident
Last reviewed
9 September 2026

What counts as an incident

  • A security defect in shipped Kenii software.
  • Unauthorized access to a Kenii vendor-side service.
  • Loss or exposure of a credential held by Kenii, including one issued by an institution.
  • Any report from an institution, a researcher or a member of the public alleging one of the above.

Reporting an incident to Kenii

Write to security@kenii.app, or use the direct contact named in your agreement. Kenii acknowledges a report within one business day.

A reporter acting in good faith is not pursued for reporting a defect.

The steps

  1. Acknowledge and record. Log the time received, the reporter, and what was claimed.
  2. Assess. Determine whether the report is valid, what it reaches, and which institutions are affected. Assign a severity.
  3. Contain. Revoke exposed credentials, disable the affected function, or take a vendor-side service offline. Containment takes priority over root cause.
  4. Notify. See the table below.
  5. Remediate. Fix the defect, validate the fix against the automated suites, release it, and tell institutions what to apply.
  6. Review. Within ten business days of closure, record what happened, what was fixed, and what changes so it does not recur.

Notification

Kenii notifies every institution running an affected version, not only the one that reported it.

Notification timing by severity
Severity Definition Notify within
Critical Unauthenticated access to institutional data, or remote code execution 24 hours of confirmation
High Authenticated privilege escalation, or exposure of a credential 3 business days
Moderate A defect requiring unusual conditions, with limited reach With the next release

Kenii will not delay notification to finish a fix. A notification states what was found, what it reaches, what an institution must do, and when a fix is available.

Legal obligations

Kenii complies with applicable breach notification law and with notification terms in the institutional agreement, whichever requires action sooner. Where an institution must notify individuals, Kenii supplies the facts that institution needs.

The limit worth stating

Because institutional data resides on institutional infrastructure, most breach scenarios in a Kenii deployment are breaches of the institution’s environment, which Kenii cannot detect and does not monitor.

This document covers what Kenii can see: its own services, its own code, and its own credentials. Detection inside the institution’s environment remains the institution’s.

Report somethingto security@kenii.app.

Acknowledged within one business day. Good-faith reporters are never pursued.