Security

Vulnerability Disclosure Policy

How to responsibly report a security vulnerability affecting a Cybecs public system.

Reporting a vulnerability

If you believe you've found a security vulnerability affecting a Cybecs public system, including cybecs.com, please report it responsibly to [email protected]. Include enough detail for us to reproduce the issue: the affected URL or system, the steps you took, and what you observed.

What we ask

  • Give us a reasonable amount of time to investigate and respond before disclosing publicly.
  • Avoid actions that could harm the availability or integrity of our systems or data, including denial-of-service testing.
  • Avoid accessing, modifying, or exfiltrating data beyond what's necessary to demonstrate the issue.
  • Do not attempt social engineering, phishing, or physical-access attacks against Cybecs staff or facilities.

What this policy does not authorize

This policy does not grant permission for intrusive testing, exploitation beyond proof-of-concept, denial-of-service testing, credential-stuffing or brute-force attacks, social engineering, or access to data belonging to other users or clients. Testing scope beyond good-faith identification and reporting of a vulnerability requires our explicit prior authorization.

Our response

We aim to acknowledge reports sent to [email protected] in a reasonable timeframe and to keep you informed as we investigate. We do not currently operate a paid bug bounty program.

Effective date: August 31, 2026.