Home / Responsible Disclosure

Security

Found a problem in our systems? Tell us.

Good-faith research is welcome and protected. Here is our scope, our response times, and our commitments to you.

// Last updated 3 September 2026

We are a security firm. It would be poor form to ask others to accept vulnerability reports gracefully and then not do it ourselves. If you have found a security issue in a CyberIntelix system, we want to hear about it, and we will not take legal action against you for telling us in good faith.

Scope

In scope: cyberintelix.com and its subdomains, and any service we operate directly.

Out of scope: systems belonging to our clients. We cannot authorise testing against a client environment, and we will not accept reports that required you to test one. If you believe you have found an issue affecting a CyberIntelix client, tell us and we will route it to them — do not probe further.

How to report

Email security@cyberintelix.com with enough detail to reproduce the issue: the affected URL or endpoint, the steps, and the impact you believe it has. A proof-of-concept helps. Please send it to us before you send it anywhere else.

What we ask of you

  • Give us reasonable time to fix the issue before publishing it.
  • Use only the minimum access needed to demonstrate the problem, and stop as soon as you have.
  • Do not access, modify, download, or retain data that is not yours. If you encounter personal data, stop and tell us immediately.
  • No denial of service, no spam, no social engineering of our staff or suppliers, and no physical attacks.

What you can expect from us

  • Within 3 working days: acknowledgement that a human has your report.
  • Within 10 working days: our assessment of validity and severity, and an indicative fix timeline.
  • On resolution: confirmation that it is fixed, and public credit if you would like it and the finding warrants it.

We do not currently operate a paid bug bounty. We will always credit researchers who want to be named.

Safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised, we will not pursue or support legal action against you over it, and we will work with you if a third party does. If you are unsure whether something is in scope, ask us first at security@cyberintelix.com.