Email support@krellix.app with the subject line "Security disclosure." A human responds within one business day. Critical issues — anything that could compromise a customer's collection — are acknowledged within four hours during US business hours.
We commit to working with reporters in good faith, not pursuing legal action against reporters who follow this disclosure process, and crediting reporters publicly if they want credit. No bug bounty yet — Krellix is early — but we'll send a bottle of something nice and a hand-written thank-you note for anything meaningful.
A standard /.well-known/security.txt file is published at the site root with the same contact information.