Skip to content

Responsible disclosure

Found something? Tell us properly.

We test other organisations' systems for a living, so we hold our own to the standard we ask of clients. If you have found a security issue in anything we run, here is how to report it and what we owe you in return.

Report to
support@cybaethrex.com
Acknowledgement
1 business day
Triage
5 business days
Safe harbour
Yes, in good faith
01How to report

One email, with as much detail as you have.

No portal, no account, no bug bounty platform in the way.

Email support@cybaethrex.com with the affected URL or component, the steps to reproduce, and what an attacker could achieve. A short proof of concept helps more than a long description. If the issue is sensitive, say so in the first line and we will move to an encrypted channel before you send details.

Please give us a reasonable window to fix the issue before disclosing it publicly. We will agree a date with you rather than impose one, and we will not ask you to stay quiet indefinitely.

02What we commit to

Our side of the exchange.

01

Acknowledge within one business day

You will get a human reply confirming receipt, not an automated ticket number.

02

Triage within five business days

We will tell you whether we can reproduce the issue, how we have rated it, and what we intend to do about it.

03

Keep you informed until it is closed

You will hear from us at each state change rather than having to chase for status.

04

Credit you if you want it

We will name you in the fix note, or keep you anonymous. Your choice, and we will ask explicitly.

03Scope

In scope

  • cybaethrex.com and its subdomains
  • Any service we operate that handles client or candidate data
  • Our published tooling and code repositories

Out of scope

  • Findings in client systems reached through our engagements. Report those to the client, or to us in confidence and we will route them
  • Volumetric denial of service, or any test that degrades availability for others
  • Social engineering of our people, suppliers or clients
  • Reports generated solely by an automated scanner with no demonstrated impact
  • Missing hardening headers or configuration weaknesses with no exploitable consequence
04Safe harbour

Research in good faith is welcome, not litigated.

If you follow this policy, act in good faith, avoid privacy violations and service degradation, and only interact with accounts you own or have explicit permission to test, we will not pursue or support legal action against you for your research.

If a third party brings action against you for work carried out within this policy, tell us and we will make our position clear: that the research was authorised.

This policy covers systems Cybaethrex operates. It does not grant permission to test any client system, whether or not you believe we work with them.

Security contact

Reporting something urgent?

Put URGENT in the subject.

Send it to support@cybaethrex.com and we will pick it up the same working day. If you need an encrypted channel, say so and we will arrange one before you send any details.