Home / Responsible Disclosure
Security
Good-faith research is welcome and protected. Here is our scope, our response times, and our commitments to you.
// Last updated 3 September 2026
We are a security firm. It would be poor form to ask others to accept vulnerability reports gracefully and then not do it ourselves. If you have found a security issue in a CyberIntelix system, we want to hear about it, and we will not take legal action against you for telling us in good faith.
In scope: cyberintelix.com and its subdomains, and any service we operate directly.
Out of scope: systems belonging to our clients. We cannot authorise testing against a client environment, and we will not accept reports that required you to test one. If you believe you have found an issue affecting a CyberIntelix client, tell us and we will route it to them — do not probe further.
Email security@cyberintelix.com with enough detail to reproduce the issue: the affected URL or endpoint, the steps, and the impact you believe it has. A proof-of-concept helps. Please send it to us before you send it anywhere else.
We do not currently operate a paid bug bounty. We will always credit researchers who want to be named.
If you make a good-faith effort to follow this policy, we will treat your research as authorised, we will not pursue or support legal action against you over it, and we will work with you if a third party does. If you are unsure whether something is in scope, ask us first at security@cyberintelix.com.