Security
Report a security issue
Keeping your crew’s conversations safe matters to us. If you think you’ve found a vulnerability in KeyUp, please tell us. We’d much rather hear about it from you first.
Email [email protected] with “Security” in the subject line.
Include what you found, where (app, version, URL or endpoint), steps to reproduce, and the impact you think it has. Screenshots, a short video or a proof of concept help a lot.
What we’ll do
- Acknowledge your report within 3 business days.
- Keep you updated as we investigate and fix it.
- Let you know when it’s fixed, and credit you publicly if you’d like.
- Not pursue legal action against good-faith research that follows this policy.
In scope
- The KeyUp Android app and Wear OS app (current beta builds from Google Play).
- The KeyUp web app and guest pass links.
- KeyUp APIs and real-time voice relay used by the apps.
- This website, keyupradio.com, including the beta sign-up form.
Especially interesting: accessing another person’s Space, room, audio, messages, recordings or transcripts; bypassing guest pass expiry or room permissions; account takeover; leaking AI API keys; and anything that lets you listen in without being shown in the room.
Out of scope
- Denial-of-service or load testing, spam, and social engineering of KeyUp staff or users.
- Physical attacks, or attacks that need a rooted/jailbroken or already-compromised device.
- Issues in third-party services (for example Google Play, Firebase or an AI provider). Please report those to them.
- Missing best-practice headers or TLS settings with no demonstrated impact, clickjacking on pages with no sensitive actions, and self-XSS.
- Reports from automated scanners without a working proof of concept.
Please
- Only test against accounts and Spaces you own or have permission to test.
- Don’t access, change or keep other people’s data. If you hit some by accident, stop and tell us.
- Give us reasonable time to fix the issue before sharing it publicly.
How we protect KeyUp
- All traffic between the apps and our servers is encrypted in transit, and our servers use encrypted storage. KeyUp is not end-to-end encrypted.
- Recording, transcripts and AI are off by default, and visible to everyone in a room when on.
- AI API keys are stored encrypted and only used for the requests your Space makes.
- Guest passes only open the rooms they were made for, always expire (after 1 hour to 1 week), and can be turned off at any time.
For how we handle personal data, see our Privacy Policy.