Security

Report a security issue

Last updated September 28, 2026

Keeping your crew’s conversations safe matters to us. If you think you’ve found a vulnerability in KeyUp, please tell us. We’d much rather hear about it from you first.

Email support@keyupradio.com with “Security” in the subject line.

Include what you found, where (app, version, URL or endpoint), steps to reproduce, and the impact you think it has. Screenshots, a short video or a proof of concept help a lot.

What we’ll do

  • Acknowledge your report within 3 business days.
  • Keep you updated as we investigate and fix it.
  • Let you know when it’s fixed, and credit you publicly if you’d like.
  • Not pursue legal action against good-faith research that follows this policy.

In scope

  • The KeyUp Android app and Wear OS app (current beta builds from Google Play).
  • The KeyUp web app and guest pass links.
  • KeyUp APIs and real-time voice relay used by the apps.
  • This website, keyupradio.com, including the beta sign-up form.

Especially interesting: accessing another person’s Space, room, audio, messages, recordings or transcripts; bypassing guest pass expiry or room permissions; account takeover; leaking AI API keys; and anything that lets you listen in without being shown in the room.

Out of scope

  • Denial-of-service or load testing, spam, and social engineering of KeyUp staff or users.
  • Physical attacks, or attacks that need a rooted/jailbroken or already-compromised device.
  • Issues in third-party services (for example Google Play, Firebase or an AI provider). Please report those to them.
  • Missing best-practice headers or TLS settings with no demonstrated impact, clickjacking on pages with no sensitive actions, and self-XSS.
  • Reports from automated scanners without a working proof of concept.

Please

  • Only test against accounts and Spaces you own or have permission to test.
  • Don’t access, change or keep other people’s data. If you hit some by accident, stop and tell us.
  • Give us reasonable time to fix the issue before sharing it publicly.

How we protect KeyUp

  • All traffic between the apps and our servers is encrypted in transit, and our servers use encrypted storage. KeyUp is not end-to-end encrypted.
  • Recording, transcripts and AI are off by default, and visible to everyone in a room when on.
  • AI API keys are stored encrypted and only used for the requests your Space makes.
  • Guest passes only open the rooms they were made for, always expire (after 1 hour to 1 week), and can be turned off at any time.

For how we handle personal data, see our Privacy Policy.