Responsible disclosure policy.
This is our current published policy. For contractual agreements (DPA, MSA), contact hello@cyfriq.com.
Security is core to what we build, and we welcome reports from the research community. If you believe you have found a vulnerability in a Cyfriq system, this policy explains how to report it, what is in scope, and what you can expect from us in return.
Our commitment
We value the work of security researchers who help keep our customers safe. We will investigate every legitimate report we receive, respond in good faith, and work to remediate confirmed issues in a reasonable timeframe.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorised. This safe harbour applies only to research that stays within the scope and rules described below.
Scope
This policy applies to the Cyfriq website at cyfriq.com and to the internet-facing services we operate. If you are unsure whether a target is in scope, ask us at security@cyfriq.com before testing.
Out of scope
The following are not authorised under this policy:
- Denial-of-service (DoS or DDoS) attacks, or any testing that degrades, disrupts or exhausts the availability of our services.
- Social engineering, phishing, or any attempt to obtain credentials from our staff, customers or contractors.
- Physical attacks against our offices, staff or infrastructure.
- Accessing, modifying, deleting or exfiltrating data that does not belong to you, or attempting to access another customer's or user's data.
- Automated scanning that generates excessive traffic, and spam or bulk-submission of forms.
- Findings that affect third-party services we do not operate; report those to the relevant provider.
How to report
Send your report by email to security@cyfriq.com. Our security contact details are also published, in machine-readable form, at /.well-known/security.txt. Please do not disclose the issue publicly until we have had a reasonable opportunity to address it.
What to include
To help us triage and reproduce the issue quickly, please include:
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce it.
- The affected URL, endpoint, parameter or component, and any relevant version information.
- Any proof-of-concept, screenshots or logs that demonstrate the issue, without including more sensitive data than necessary.
Our response commitment
We aim to acknowledge your report within a few business days, keep you informed as we investigate, and let you know when the issue is resolved. With your permission, we are happy to credit you for a valid, previously unreported finding. We do not currently run a paid bug-bounty programme, and reports are handled on the terms set out here.
Guidelines for researchers
Act in good faith, avoid privacy violations and service disruption, and only interact with accounts you own or have explicit permission to test. Access only the minimum data needed to demonstrate a finding, and delete any such data once you have reported it. Give us a reasonable period to remediate before any public disclosure, and coordinate the timing with us.
Questions?
For anything relating to security or vulnerability reporting, contact us at security@cyfriq.com.