Skip to content
Khepee is coming soon — we are onboarding partner institutions now.Get early access →
Khepee
  • Lending lifecycle

    • Platform overviewThe whole stack, end to end
    • OriginationApply in minutes, decide in one queue
    • Digital KYCDocument capture, liveness, verification
    • recommendationCredit decisioningScorecards that assist, never replace

    Money & servicing

    • on your railsDisbursementOrchestrated on your rails
    • Servicing & collectionsEMI schedules, reminders, recovery
    • NRBReportingPortfolio views and NRB extracts
    • Borrower appiOS and Android, in Nepali and English
    Built to NRB rules from line one

    Loan ceilings, the 36-month cap and the KYC gate are enforced in code, not in a policy document.

    How compliance works →
  • By institution

    • For banks & FIsClass A, B and C institutions
    • For microfinanceClass D, group and individual lending
    • For cooperativesMember-based lending, digitised

    By outcome

    • Digital transformationFrom paper files to a live portfolio
    • Risk managementConsistent decisions, complete evidence
    • For borrowersWhat to expect from a Khepee loan
    You hold the licence. We hold the tech.

    No NRB application from your side. No capital from ours. The partnership works because each side brings what the other lacks.

    See how the partnership works →
  • Compliance

    • NRB complianceEvery rule, and how the code enforces it
    • Audit trailAppend-only, examiner-ready
    • Data protectionPurpose-bound borrower data

    Engineering

    • SecurityEncryption, access control, testing
    • TechnologyThe stack and why it was chosen
    • ReliabilityAvailability and recovery commitments
    Read the legal terms

    Twelve documents covering terms, privacy, AML, grievance redressal and the code of conduct. Each downloadable as a signed PDF.

    Legal centre →
  • About

    • About KhepeeWhy this exists
    • LacspaceThe company behind Khepee
    • CareersBuild it with us

    Resources

    • FAQStraight answers
    • InsightsNotes on lending in Nepal
    • ContactTalk to a person
  • Pricing
LegalTalk to us
Platform

Lending lifecycle

  • Platform overview
  • Origination
  • Digital KYC
  • Credit decisioning

Money & servicing

  • Disbursement
  • Servicing & collections
  • Reporting
  • Borrower app
Solutions

By institution

  • For banks & FIs
  • For microfinance
  • For cooperatives

By outcome

  • Digital transformation
  • Risk management
  • For borrowers
Trust

Compliance

  • NRB compliance
  • Audit trail
  • Data protection

Engineering

  • Security
  • Technology
  • Reliability
Company

About

  • About Khepee
  • Lacspace
  • Careers

Resources

  • FAQ
  • Insights
  • Contact
PricingLegal centreTalk to us
  1. Home
  2. Legal
  3. Security disclosure

Legal document · v1.0

Vulnerability Disclosure Policy

How to report a security vulnerability, what we commit to in return, and what is out of scope.

Published
30 July 2026
Status
In force
Version
1.0
Length
4 sections · 20 clauses
Download PDFAll documents

Contents

  1. 1. Reporting
  2. 2. Safe harbour
  3. 3. Scope
  4. 4. What we do with a report

In plain language

This summary is provided to help you understand the document. It is not a substitute for the formal text below, which governs.

  • Report to security@khepee.com. We acknowledge within two business days.
  • Good-faith research following this policy will not be met with legal action.
  • Do not access other people’s data, and do not test in production against real borrowers.
  • We will credit you if you want it.

1Reporting

  1. 1.1

    Where

    security@khepee.com. If the issue is sensitive, say so and we will arrange an encrypted channel.

  2. 1.2

    What to include

    The affected component, reproduction steps, the impact you believe it has, and any proof of concept. Clear reports get fixed faster.

  3. 1.3

    Acknowledgement

    Within two business days of receipt.

  4. 1.4

    Progress updates

    At least every ten business days until resolution or a decision not to act, with reasons.

  5. 1.5

    Disclosure timing

    We ask for ninety days before public disclosure, or sooner if we have fixed and deployed. If we need longer we will explain why rather than go quiet.

2Safe harbour

  1. 2.1

    No legal action

    We will not pursue legal action against anyone who acts in good faith and follows this policy.

  2. 2.2

    Good faith means

    Avoiding privacy violations and service degradation, not accessing or modifying data belonging to others, and stopping as soon as you have demonstrated the issue.

  3. 2.3

    If you go too far

    Accessing another person’s data beyond what is needed to demonstrate a flaw, or exfiltrating data, falls outside this policy.

  4. 2.4

    Third parties

    This safe harbour covers systems we operate. It cannot bind our partner institutions or service providers.

3Scope

  1. 3.1

    In scope

    The khepee.com website, the Khepee borrower application, the operations console and the platform API.

  2. 3.2

    Out of scope

    Systems operated by partner institutions, third-party services, and anything hosted on a domain we do not control.

  3. 3.3

    Do not test in production against real data

    Do not attempt to access real borrower records. Ask us for a test environment; we would rather provide one than have you probe live data.

  4. 3.4

    Prohibited techniques

    Denial of service, social engineering of our staff or partners, physical attacks, and spam.

  5. 3.5

    Low-severity findings

    Missing best-practice headers with no demonstrable impact, self-XSS, and issues requiring a fully compromised device are generally accepted risks rather than vulnerabilities. Report them anyway if you disagree — we will explain our reasoning.

4What we do with a report

  1. 4.1

    Triage

    We assess severity and impact, and tell you our assessment.

  2. 4.2

    Fix

    Critical issues are addressed as a priority. We will tell you when a fix is deployed.

  3. 4.3

    Partner notification

    Where a vulnerability could have affected partner data, we notify the affected institutions.

  4. 4.4

    Credit

    We are glad to credit reporters publicly. Tell us how you would like to be named, or that you would prefer not to be.

  5. 4.5

    Rewards

    We do not currently run a paid bounty programme, and we will not imply otherwise. If that changes it will be published here.

  6. 4.6

    Honest position

    Khepee is pre-launch and has not yet had an independent penetration test. Reports from researchers are genuinely valuable to us at this stage, and will be treated that way.

§Document control

  1. A

    Publisher

    Lacspace Corporation Pvt. Ltd., Kathmandu, Nepal. Published at khepee.com/legal/vulnerability-disclosure.

  2. B

    Version and commencement

    Version 1.0, published 30 July 2026, last updated 30 July 2026. This document is in force and applies from the date of publication shown above. Superseded versions are retained and available on request from legal@khepee.com.

  3. C

    Standing disclaimer

    Khepee is a technology service provider operated by Lacspace Corporation Pvt. Ltd. It is not a bank or financial institution. It does not lend, does not accept deposits and does not hold customer funds. Lending products are provided by partner institutions licensed by Nepal Rastra Bank, and all credit decisions are theirs.

  4. D

    Language

    Published in English. Any translation is for convenience only; the English version governs in the event of inconsistency.

Related documents

  • Terms of ServiceThe terms governing use of the Khepee website, borrower app and platform — including the crucial point that Khepee is not your lender.
  • Privacy PolicyWhat personal data we collect, why, who can see it, how long we keep it, and the rights you have over it.
  • Regulatory Disclosures & WarningsKhepee’s regulatory position stated in full: what we are, what we are not, the NRB rules the platform enforces, and the risk warnings every borrower should read.
  • Borrower Rights CharterWhat every borrower is entitled to expect — written for borrowers rather than for institutions, and enforceable through the grievance process.
  • Code of ConductThe standards we hold ourselves and our partners to — particularly around collections, borrower treatment and honest representation.
  • Grievance Redressal PolicyHow to complain, who handles it, how long it takes, and how to escalate — including to Nepal Rastra Bank where your lender is involved.
Khepee

Lending infrastructure for Nepal · नेपालको लागि कर्जा पूर्वाधार

A product of Lacspace

hello@khepee.com+977 9705 300600Kathmandu, Nepal

Platform

  • Overview
  • Origination
  • Digital KYC
  • Credit decisioning
  • Disbursement
  • Servicing
  • Reporting
  • Borrower app

Solutions

  • For banks & FIs
  • For microfinance
  • For cooperatives
  • Digital transformation
  • Risk management
  • For borrowers
  • How the partnership works
  • Pricing

Trust

  • NRB compliance
  • Audit trail
  • Data protection
  • Security
  • Technology
  • Reliability

Company

  • About
  • Lacspace
  • Careers
  • Insights
  • FAQ
  • Contact

Important. Khepee is a technology service provider operated by Lacspace Corporation Pvt. Ltd. It is not a bank or financial institution. It does not lend, does not accept deposits and does not hold customer funds. Lending products are provided by partner institutions licensed by Nepal Rastra Bank, and all credit decisions are theirs. Khepee makes no claim of licensing, approval, registration or endorsement by Nepal Rastra Bank or any other regulator. Nothing on this website constitutes an offer of credit, financial advice, or a commitment to lend.

© 2026 Lacspace Corporation Pvt. Ltd.
TermsPrivacyDisclosuresBorrower rightsConductGrievancesAll legal documents