Security Policy
Effective date: July 1, 2026 · Version 1.0
1. Security architecture
Kairon runs each site in an isolated renderer process (site isolation), sandboxes renderer processes from direct system access, and applies IPC flood protection to limit how fast a renderer can message the privileged browser process.
2. Patch commitments
Confirmed vulnerabilities are fixed and shipped in a subsequent release as quickly as we reasonably can. Because the browser is in beta, fixes are delivered through new beta releases rather than on a fixed patch schedule.
3. No extensions
Kairon does not support extensions, so there is no third-party code running inside the browser and no extension store or review process to compromise.
4. Incident response
Confirmed security incidents affecting user data are investigated, contained, and disclosed to affected users without undue delay, consistent with applicable breach-notification law.
5. Reporting a vulnerability
See the Responsible Vulnerability Disclosure Policy for how to report a security issue and what to expect from us in response.