Responsible disclosure.
A clear route for reporting potential vulnerabilities affecting systems operated by CyberAI.
How to report
Email CyberAI with a clear description, affected URL or component, reproduction steps, impact and supporting evidence. Do not include unnecessary personal data.
Scope
Only systems and domains explicitly operated by CyberAI are in scope. Third-party infrastructure and partner systems are excluded unless written permission states otherwise.
Safe-harbour conditions
Avoid privacy violations, service disruption, data destruction and social engineering. Use the minimum testing necessary to demonstrate the issue and do not publicly disclose before a reasonable remediation period.
Response process
CyberAI will acknowledge valid reports when operationally possible and coordinate remediation based on severity and available resources.
Bring a defined research or engineering challenge.
Share the system context, expected result, timeline and collaboration route.