Research policy

Security research traffic from KSI Digital

If you found research-scanner in your server logs, the request came from the KSI Digital security research team. This page explains what that traffic is, what it does and does not do, and how to reach us or ask us to stop.

1Who we are

KSI Digital (PT Karunia Solusi Informatika) is a technology company based in Jakarta, Indonesia. Our security research team looks for vulnerabilities in internet-facing systems and reports them to the people who can fix them, through vulnerability disclosure and bug-bounty programs, and for clients who engage us to review their own systems.

2What this traffic is

It is authorized security research. We test only two kinds of system:

  1. Bug-bounty and vulnerability-disclosure programs whose published rules allow automated testing, and only within each program's stated scope, exclusions, testing window and rate limits.
  2. Client systems under written authorization. The authorization names who signed it and the agreement it belongs to, lists the assets we may test, and has a start and end date.

An authorization check runs before any request reaches a host. It refuses, and we do not test, when:

For client work, the check refuses any host outside the signed list of assets, any request outside the authorized dates, and any authorization without a named signatory. A withdrawn authorization takes effect from the next decision.

Our control plane records every authorization decision, including every refusal, in an append-only audit log.

3What our scanner does and does not do

What it does

What it does not do

Rate limits

By default we send no more than one request per second to a host. For client work we hold to the rate agreed with the client, and where a program states its own limit we stay within it. Retries count toward that limit. If a tool cannot run slowly enough to stay within it, the check is skipped rather than run faster.

People, not automation, decide what is reported

Automated checks only flag candidates. A researcher reviews each one, confirms the issue and prepares any proof of concept before anything is reported.

4How to recognize our traffic

User-Agent

Our detection checks identify themselves with this User-Agent header:

research-scanner/1.0 (+https://research.ksi-digital.com/about; research@ksi-digital.com)

The version number may change; the research-scanner/ prefix, the link to this page and the contact address do not. Anyone can copy a User-Agent, so the source address below is the more reliable signal.

Source IP addresses

https://research.ksi-digital.com/ips.txt lists the IP addresses our scanning servers send from, one per line. It is the authoritative list and we keep it current. Each scanning server has a fixed address, and each host is assigned to one scanning server at a time, so you should see one of our addresses rather than many. The list is empty at the moment because our scanning servers are not yet in service.

One exception: an occasional single header check — one HTTPS GET of a site's home page, without following redirects, after the same authorization check — is sent from Cloudflare's network instead. It carries the same User-Agent.

You are welcome to block the addresses in the list. We do not try to get around blocks.

5Ask us to stop, or report a problem

Email us with the hostnames or IP addresses concerned and, if you have them, a timestamp and the source address from your logs. We will stop testing the hosts you name and confirm by email. We aim to reply within two business days (Jakarta time, UTC+7). If our traffic is causing a problem right now, put URGENT in the subject and we will deal with it first.

If you run a bug-bounty or disclosure program and believe we have acted outside its rules, please also tell us through the platform, so the program has a record.

6How we disclose findings

7Contact

research@ksi-digital.com

Machine-readable contact details: /.well-known/security.txt. Company information: ksi-digital.com.