Skip to content

Responsible disclosure

Security disclosure policy for CyberBit Solutions.

CyberBit welcomes good-faith reports about security concerns on the public website. This policy keeps the reporting scope clear and helps protect customers, visitors, and researchers.

Version 2026-07-20 | Effective July 20, 2026 | Last updated July 20, 2026

Reporting is not authorization to test.

This policy is for reporting a suspected concern in CyberBit's public website. It does not authorize active testing of customer, vendor, third-party, private, or unspecified systems. CyberBit's commercial Authorized Web Application Penetration Test uses a separate qualification, executed agreement, verified scope, written Authorization to Test, and Rules of Engagement before any testing begins.

In scope for reporting

In scope identifies concerns CyberBit is prepared to receive. It is not blanket permission for active or invasive testing.

  • Reports about the CyberBit Solutions public website and public web assets.
  • Clear reproduction steps, the affected URL, browser details, timestamps, and screenshots when useful.
  • Good-faith reporting that avoids harm, disruption, and access to data that is not yours.

Out of scope and prohibited

  • Testing systems, accounts, vendors, customers, or infrastructure outside the public CyberBit website without written permission.
  • Destructive testing, denial-of-service testing, request flooding, spam, or actions that degrade service availability.
  • Credential attacks, password guessing, credential stuffing, phishing, social engineering, or physical attacks.
  • Data exfiltration, attempts to access private data, persistence, malware, or destructive changes.
  • Testing a third-party service or customer system based only on its connection to CyberBit.
  • Public disclosure before CyberBit has reviewed the report.

When to stop

Minimize data and impact. A possible issue is not permission to continue into private or unrelated areas.

  • Stop if ownership, authorization, or scope becomes uncertain.
  • Stop if you reach a third-party-controlled or nonpublic system.
  • Stop if private data, credentials, secrets, customer information, or unexpected sensitive data appears.
  • Stop if the activity creates instability, service degradation, or business impact.
  • Do not copy, retain, download, alter, or share more information than is minimally necessary to describe the concern.
  • Notify CyberBit through the security email and wait for a coordinated response before taking further action.

What to include in a report

Concise, minimally sensitive evidence helps CyberBit validate and route the report safely.

  • A concise description of the concern and its potential impact.
  • The affected CyberBit URL or public asset.
  • Safe, repeatable steps that CyberBit can use to validate the concern.
  • Relevant browser, device, date, time, and network context.
  • Minimal screenshots or masked evidence when they help explain the issue.
  • A reliable contact method for follow-up.

After reporting

Allow CyberBit to review and coordinate.

CyberBit will make a good-faith effort to acknowledge valid reports and coordinate a reasonable next step. Validation, provider coordination, risk, and remediation complexity can affect timing.

Do not disclose the concern publicly before CyberBit has reviewed the report. Do not use the report or this policy to access data, disrupt services, demand access, or test a third party.

This policy does not replace a customer contract, Authorization to Test, Rules of Engagement, or a third party's own vulnerability-disclosure policy.