Security

Found something? Tell us.

Krateo holds family ledgers, kids' allowances, and transactions one family member has deliberately marked private from another. A flaw here reaches somebody's family. This page is the whole policy, including the parts that are narrower than you might expect.

How to report

Email security@krateomoney.com. Tell us what the issue is in a sentence or two, the exact steps to reproduce it, what an attacker gets out of it and whose data, where you found it, and any account or household id you used so we can find it in the logs.

If what you reached was a child's or a teen's data, tell us that first. Put CHILD DATA in the subject line, describe in words what you saw, and attach none of it. That subject line changes what happens on our side, and it is the one piece of routing we ask you to get right. Send us the least that still proves the issue: a report can end up in our logs, our records, and, where the law requires it, a regulator's file, so fewer other people's details in the email is better for them and for you.

A short email with a working reproduction beats a long one without. Please do not open a public issue or post first. We do not publish a PGP key today, so mail to that address is not end to end encrypted; if a report is sensitive enough that this matters, send a first note with no details and we will agree a channel.

Write to us in English if you can. The app ships in English, Portuguese, Spanish and French and a report in any of those is welcome, but English is the one where we can promise we have not misread you, and our reply may come back in English either way.

Read this before you start

Krateo's safe harbour is a partial one. A complete safe harbour rests on four things. Three of them are in force here. The missing one is the third, and it is the one that lives in our own contract with you. We would rather hand you an accurate, smaller promise than a generous one a lawyer could take apart.

Who is promising, and what this page is. Krateo is run by one person: Carlos Dente, an individual doing business as Krateo. The commitments here are that person's, and if the business is later moved into a company we intend them to move with it. Nobody here is a lawyer and no lawyer wrote this page, so nothing on it is legal advice. It is not a contract either, and it does not change the Terms you accepted, including the law and the courts they name. It is a public statement of how we will act, which is a smaller thing than a clause, and we would rather you know which of the two you are holding.

What we can promise

If you make a good faith effort to follow the ground rules below, then for the research covered by this policy, the four below apply. Each one is a promise about what we will do: we can give up our own claims, we cannot give up anybody else's, and we cannot bind a court, a regulator, or a prosecutor.

1. Authorised under anti-hacking law

We treat good faith research under this policy as authorised access to our systems for the purposes of computer misuse and anti-hacking law. We will not bring a claim under those laws, we will not volunteer to support or join anyone else's, and we will not report you to law enforcement. The one thing we cannot promise: if a lawful order compels us to hand over records or give evidence, we will follow the law, and we will tell you first where we are allowed to. And one thing that is not research at all, so none of this reaches it: if we ever had reason to believe a child was being harmed, we would act on that immediately, without stopping to reason about this page.

2. We will not use anti-circumvention or copyright law against you

Taking the app apart is how several of the findings we ask for get found at all. We will not raise anti-circumvention or copyright law against good faith research conducted under this policy. Read that as what it says: the claims we give up are ours. It is not a statement that reverse-engineering Krateo is permitted, because our own Terms still prohibit it, which is item 3. The Terms' clause carries its own exception where the law grants that right in spite of the term; whether it reaches your work where you live is a question for your lawyer, not one we will guess at for you.

3. Your research does not breach our Terms. THIS IS THE ONE WE CANNOT GIVE YOU.

The acceptable use section of the Terms tells every user not to probe, scan or test the app's security, not to reverse-engineer it, and not to access another household's data. Research of the kind this page asks for falls inside that clause, and a page cannot rewrite the contract you accepted. Two consequences you should hear from us rather than find later: the Terms also carry an indemnity and a termination right, and both key off a breach of the Terms; and the published Terms page states a shorter version of that clause which does not use the words probe, scan or test, as do the Portuguese, Spanish and French pages. Which text governs, and whether any of it reaches somebody who never created an account and only looked at the public website, are questions we have not had answered. We assume the wider reading and say so.

What we can promise without amending it: a good faith report is welcome rather than a Terms violation, we will not use it as grounds to suspend or terminate your account, and we will not invoke the indemnity or the termination clause over it. That is not a promise never to act on an account for any reason. Conduct outside the ground rules is not a report: exfiltration, extortion, destroying data, or using a finding to go further. If we ever do act on your account, we will tell you why.

4. Good faith is what we are judging

Accidentally crossing a line while acting in good faith does not change any of the above. Tell us what happened. Honesty about a mistake is part of the work, not an offence. If a third party brings a claim and we assess that you were acting within this policy, we will say so in writing, to them or to a court, and we will not be shy about it. What that is not: we cannot defend you, pay your costs, indemnify you, or make somebody else's claim stop.

Three of four are in force, so this stays a partial safe harbour until the Terms change. If you are deciding whether to look at Krateo at all, decide with that in front of you.

The limits, stated plainly

This covers Krateo only: we cannot waive the rights of the app stores we distribute through, our bank and broker data aggregation providers, our cloud, hosting and CDN providers, our payment and subscription providers, or another Krateo user. Their terms still apply to you, this page is not permission to test them, and nothing here protects you if you do. If a finding needs their systems to reproduce, describe it to us in words and take the finding itself to them. It does not cover extortion, deliberate exfiltration of other people's data, destroying data, or selling a finding to someone else first. It does not change the Terms, including the governing law and courts they name. It is not legal advice, nobody here is a lawyer, and it is not a contract: it creates no right you could sue us on, and it is published so you can hold us to it in the open.

Open item, dated 10 August 2026. Amending the Terms to carry an explicit security research carve-out is an owner and counsel decision that has not been made. Until it lands, tenet 3 stays missing and this page will keep saying so.

Ground rules while you test

Everything above depends on these. Use your own account and your own test household, and do not touch a household you were not invited to. Never test against a real child's account, ours or anyone else's. If you reach data that is not yours, stop immediately: do not save it, capture no more than the one line that proves the issue, tell us, and delete what you have, and where your own test data would prove the same point, use your own test data. Do not modify, corrupt, or delete data you did not create. Do not use a finding to keep access or to go further, and do not use one to reach the physical world by contacting other users, moving money, or sending mail from our systems. No automated scanning at volume against production, and no load testing.

If the data you reached belongs to or describes a child or a teen, capture nothing at all. Not one line, not a redacted screenshot, not a copy kept just in case. Describe it in words, tell us within 24 hours with CHILD DATA in the subject line, and delete every copy: drafts, notes, tool output, terminal scrollback, anything a cloud sync picked up, and your trash. If we ask you to confirm in writing that it is gone, please do. Never publish it, at any point, including after the disclosure window below has run out. A child cannot consent to being somebody's example.

If you are not sure whether something is inside these lines, ask first at security@krateomoney.com. Asking is always safe, and we would much rather answer a question than read an apology.

What we care about most

In this order: anything that reaches a child's data or reaches adult ledger data from a restricted child or teen account; anything that breaks privacy between household members; anything that reaches bank, broker or provider secrets, or another household's data; authentication and session issues; unauthenticated access to an authenticated endpoint; financial or identity data readable at rest on a device, including on a rooted or jailbroken one; and injection, broken access control, or business logic flaws that move money or corrupt a ledger.

Out of scope, not because they never matter but because we cannot act on them: third-party services themselves, denial of service and load testing, volume scanning, missing hardening with no demonstrated impact, outdated dependencies with no reachable path in Krateo, social engineering and physical attacks, self XSS, and anything that needs an already compromised device or an attacker holding the victim's unlocked signed-in phone.

In scope means Krateo's own code and configuration on the app, the server endpoints, the security rules and the website. It stops where our systems stop. The cloud platform underneath them, the hosting and the CDN, the app stores, and the provider APIs are other companies' systems: we cannot put them in scope however much we would like the finding, and we cannot give you permission to test them.

What you can expect from us

Krateo has no security team and no on-call rotation, so we are not going to promise an answer in 24 hours and then miss it. We will acknowledge your email within 5 business days, and tell you our assessment within 10: valid, not valid, or we need more from you, with the reason either way. While it is open we will update you at least every 14 days. We will tell you plainly if a fix will take months or if we decide not to fix something, and we will tell you when the fix ships. Business days means Monday to Friday in the United States, public holidays excluded. These are commitments about how we intend to act, not a service level you are buying, not a warranty, and not a contract. If we miss one, the miss is ours to name and you are free to say so in public.

Answering you and fixing the bug are two different clocks, so we publish both. Our internal targets by severity: a critical contained within 24 hours and a fix merged within 72; a high contained within 72 hours and merged within 14 days; a medium merged within 90 days; a low with no date. Two caveats that change what that is worth: only the 24 hour containment target has ever been tested by a real critical finding, and merged is not shipped because pushing to production is a separate manual step here, so there is no day count on it and we will not invent one. Whatever the targets say, anything reaching a child's data or another household's data goes to the front of the queue.

Please hold public disclosure until a fix has shipped or until 90 days from your first report, whichever comes first. If we need longer we will say so before day 90 and agree a date with you. That is a request, not a condition of anything on this page: if we cannot agree a date, publishing at 90 days is your call and we will not treat it as a breach of anything. Two things are never on that clock. Never publish another person's data, and never a child's, at any point, including after the 90 days have run. Redact it, describe it, or leave it out.

Krateo does not run a bug bounty and does not pay for reports. We would rather say that clearly than let you spend an evening assuming otherwise. What we can offer is a credit under your chosen name or handle if you want one, a straight answer about what we did with your finding, and our thanks. There is no payment now and none afterwards, and sending a report creates no expectation of one. A credit is a thank you: not an endorsement, and it makes you neither our employee nor our agent. We may decline to publish a name we cannot verify or that would be unlawful or misleading to print, and we will tell you if we do.

Some things we already know about

This list is not exhaustive, and it is not a clean bill of health. It is the small set of open issues we can describe in public without handing someone a working exploit. We are carrying other open findings that are not named here, including some in the categories above, and there are certainly ones we have not found at all.

App Check attestation is not in force: the shipped app does not attest yet, and the server records the outcome but accepts a request carrying no App Check token unless enforcement is explicitly switched on. The web build falls back to the browser's default session persistence, so unlike the native apps it does not encrypt the stored session at rest yet.

If your finding matches something already in our tracker we will tell you that plainly: that it is a duplicate, roughly when it was opened, and what is planned. We will not quietly close it as "known", and we will not pretend it was on this page when it was not.

Anything that is not a security issue

Bugs, questions, feedback, and press go to our contact page. The machine readable version of this policy is at /.well-known/security.txt (RFC 9116).

Last updated 10 August 2026.