Vulnerability Disclosure Policy
Reporting security issues
Cyber Tec Security Ltd (“CTS”) is committed to maintaining the security of our systems, services and infrastructure. We recognise the value that security researchers and members of the public provide in helping identify vulnerabilities.
This policy describes how security vulnerabilities can be reported and how Cyber Tec Security will respond to such reports.
Reporting a Security Vulnerability
If you believe you have identified a security vulnerability in any Cyber Tec Security system, service or website, please report it to:
To assist us in investigating the issue, please include:
- A description of the vulnerability
- The affected service, system or URL
- Steps required to reproduce the issue
- Any supporting evidence (logs, screenshots, proof of concept)
- A CVSS score if available (optional)
We encourage the use of the Common Vulnerability Scoring System (CVSS v3.1): https://www.first.org/cvss/calculator/3.1
Scope
This policy applies to vulnerabilities affecting:
- Cyber Tec Security websites
- Online services operated by Cyber Tec Security
- Systems directly owned and managed by Cyber Tec Security
This policy does not apply to vulnerabilities affecting third-party services or systems outside of our control.
Responsible Disclosure Expectations
To protect our customers and systems, we request that researchers:
- Act in good faith
- Avoid exploitation that could disrupt services
- Do not access, modify or delete data that does not belong to you
- Do not conduct denial-of-service attacks
- Do not publicly disclose the vulnerability until it has been resolved or a coordinated disclosure has been agreed
Our Commitment
When a vulnerability report is received, Cyber Tec Security will:
- Acknowledge receipt of the report as soon as reasonably possible.
- Investigate and verify the vulnerability.
- Assess severity and risk to our services and users.
- Develop and implement a fix or mitigation.
- Coordinate disclosure with the reporter where appropriate.
Cyber Tec Security aims to resolve confirmed vulnerabilities within 90 days where possible. If this is not achievable (for example where third-party vendors are involved), we will communicate the situation and any mitigation measures to the reporter.
Where appropriate, we will acknowledge the reporter in release notes or security advisories unless anonymity is requested.
Coordinated Disclosure
We request that vulnerability reports remain confidential during the investigation and remediation process.
Cyber Tec Security supports coordinated disclosure and will work with reporters to determine an appropriate timeline for public disclosure once a fix or mitigation has been implemented.
Safe Harbour
Cyber Tec Security will not pursue legal action against individuals who:
- Report vulnerabilities in good faith
- Follow this policy
- Avoid actions that could harm Cyber Tec Security, its customers, or its services
Testing must remain limited to identifying vulnerabilities and must not result in data exposure, service disruption or unauthorised system access beyond what is necessary to demonstrate the issue.
Vulnerabilities Identified by Cyber Tec Security
When Cyber Tec Security identifies vulnerabilities in third-party products or services, we follow a coordinated disclosure process:
- Our vulnerability analysis team will assess and verify the issue.
- The relevant vendor will be contacted and provided with the vulnerability details.
- We will work with the vendor to allow time for remediation.
- Where appropriate, an advisory may be published after 90 days, or sooner if the vendor releases a patch.
Advisories may be published through Cyber Tec Security communications channels where disclosure is considered beneficial to the security community.
Recognition
Cyber Tec Security appreciates the work of responsible security researchers and others who help us improve the security of our services.
Where appropriate, contributors may be acknowledged publicly unless they request anonymity.
Contact
All vulnerability reports and security issues should be sent to: [email protected]