Vulnerability Disclosure Policy
Purpose
CyberBlink welcomes responsible reports of potential security vulnerabilities. This page explains how to report a suspected vulnerability in CyberBlink's services and what to expect from us.
How to report
Send reports to security@cyberblinksecurity.com. This address is monitored specifically for security reports.
security@cyberblinksecurity.comWhat to include
Where possible, please include:
- A description of the issue and its potential impact
- Steps to reproduce it, including relevant requests, payloads, or screenshots
- The URL, page, or feature affected
- Any tools you used
- Whether you've disclosed this issue anywhere else
Scope
In scope
- CyberBlink's production web application and its publicly reachable pages and account features
Out of scope
- Third-party services and infrastructure we rely on but don't directly control, unless the issue is in how CyberBlink specifically integrates with them
- Social engineering or physical attacks against CyberBlink people or facilities
- Denial-of-service or resource-exhaustion testing
- High-volume automated scanning without prior coordination with us
Responsible testing
Please:
- Avoid actions that could degrade the service for other users, including denial-of-service testing or high-volume scanning
- Avoid accessing, modifying, or deleting data that isn't yours
- Use a test account you control rather than a real user's account wherever possible
- Stop and report immediately if you gain access to data that isn't yours, viewing no more than necessary to confirm the issue
Coordinated disclosure
Please give us a reasonable opportunity to investigate and address a report before disclosing it publicly. We're committed to working with researchers throughout that process.
Privacy
We handle information submitted in vulnerability reports for security investigation, remediation, and related operational or legal purposes. We limit access and disclosure to those who reasonably need the information for those purposes or where disclosure is required by law.
What to expect from us
We aim to acknowledge valid security reports and communicate as appropriate during our investigation. Response and remediation times depend on the nature and complexity of the issue, and we do not currently guarantee fixed response or resolution times.
This is a coordinated disclosure program, not a paid bug bounty program. We do not offer monetary rewards, compensation, or prizes for reports made through this channel.