Legal

Cyberr Coordinated Vulnerability Disclosure Policy

Effective date: June 15, 2026

Welcome, and thank you

Cyberr is a community for cybersecurity professionals, and we know that the people we serve are also the people most likely to find — and report — security issues in what we build. We welcome that.

This Coordinated Vulnerability Disclosure Policy (the "CVD Policy") sets out how to report a vulnerability in the Cyberr Service, what we promise in return, and the rules of engagement that frame good-faith research.

If you are reading this with a finding to report, please go straight to Section 4. If you are checking whether something you are about to do is permitted, please read Sections 2, 3 and 6 first.

1. How this policy fits in

This CVD Policy is referenced in our User Agreement and forms part of it. Defined terms used here (such as "Account", "Member", "Service") have the meanings given in the User Agreement.

Conduct that strictly complies with this CVD Policy will not be treated as a violation of Sections 6.2 or 6.3 of the User Agreement, and Cyberr will not pursue legal action against you in respect of such conduct (see Section 7 below for the full safe-harbour terms).

This CVD Policy does not cover vulnerabilities in third-party products, services or platforms, even if those are integrated with the Service. For those, please report directly to the relevant vendor or maintainer; the rules in our Community Guidelines on the public discussion of third-party vulnerabilities continue to apply.

2. In scope

The following assets are in scope of this CVD Policy:

  • Web - cyberr.ai and its subdomains operated directly by Cyberr SA (including platform.cyberr.ai, or any further such domain or subdomain which may be added to the Service from time to time, subject to the exclusions in Section 3 (in particular newly deployed, experimental, staging and third-party assets));
  • Mobile - the official Cyberr iOS and Android applications, as published by Cyberr SA in the Apple App Store and Google Play;
  • Infrastructure - back-end systems operated directly by Cyberr SA in support of the above.

If in doubt about whether a specific asset is in scope, please ask before you test, using the address in Section 4.

3. Out of scope

The following are out of scope and should not be tested under this CVD Policy, even if they are technically reachable from in-scope assets:

  • Third-party services and infrastructure integrated with the Service — including (without limitation) Mixrank, Veriff, our cloud providers, our payment providers, our email and messaging providers, our analytics providers, and any other vendor whose service the Service relies on. Vulnerabilities in such third parties should be reported directly to them, in accordance with their own policies;
  • Other Cyberr offerings — the SaaS and recruitment products operated by Cyberr for its enterprise clients are governed by separate agreements; please do not test those without the relevant client's express authorisation;
  • Social engineering of Cyberr staff, contractors, partners or Members — including phishing, vishing, smishing, pretexting, impersonation, in-person approaches and bribery;
  • Physical security of Cyberr offices, data centres or staff;
  • Denial-of-service testing — including resource-exhaustion, traffic flooding and rate-limit-bypass-at-scale;
  • Spam, brute force on Member accounts that you do not control, and credential-stuffing attacks;
  • Newly deployed or experimental assets that are clearly labelled as such (for example, behind a staging. or experiment. subdomain) — please get in touch before testing those;
  • Vulnerabilities arising solely from a Member's own end-user environment — for example, a malware-infected device, a hostile browser extension, an outdated operating system or a manipulated DNS resolver.

4. How to report

Send your report to security@cyberr.ai, encrypted with our PGP key, available at:

If PGP is impractical for you, an unencrypted report is acceptable, but please avoid including in plain text any data of identifiable individuals or any working exploit payload.

A useful report typically contains:

  • a short title naming the issue and the affected component;
  • a clear description of the vulnerability and its impact;
  • step-by-step reproduction instructions;
  • proof-of-concept code or screenshots, kept to the minimum necessary to demonstrate the issue;
  • the date and time (UTC) of testing;
  • the IP addresses, user-agents and any test accounts you used;
  • your suggested severity (CVSS where appropriate) and any mitigation suggestion;
  • how you would like to be credited (or not).

You may report under a pseudonym; we will not require you to identify yourself for us to engage with the report.

5. What we will do

When we receive your report, we will:

  • acknowledge receipt within two business days;
  • triage the report and confirm whether we consider the issue in scope, typically within five business days of acknowledgment;
  • keep you informed of progress at reasonable intervals;
  • aim to remediate confirmed vulnerabilities within timelines that reflect their severity, with critical issues prioritised;
  • coordinate the timing of public disclosure with you, in accordance with Section 8;
  • credit you, where you have asked us to and where this is reasonable in the circumstances;
  • where appropriate, coordinate with relevant computer security incident response teams (CSIRTs) and with ENISA in accordance with applicable law.

If we conclude that a report is out of scope, that the behaviour is intended, that the issue is already known or that the issue is a duplicate, we will tell you and explain why.

6. Rules of engagement

Good-faith research within this policy means:

  • Test only on assets in scope. Section 3 means what it says.
  • Use your own test accounts. If you need to test a flow that requires multiple accounts (for example, a privacy boundary between two Members), create the additional test accounts yourself; do not access an Account that does not belong to you.
  • Stop at the proof. Once you have demonstrated the existence of a vulnerability, stop. Do not enumerate the entire user base, exfiltrate datasets, escalate persistence or pivot.
  • Minimise exposure to other Members' data. If your testing inadvertently reveals data of identifiable individuals other than your own test accounts, stop immediately, retain only what is strictly needed to substantiate the report, and disclose this promptly to us. We will agree with you a process for the secure deletion of any such data.
  • Do not modify or destroy data belonging to Cyberr or to other Members.
  • Do not degrade the Service. No DoS, no resource exhaustion, no high-rate automated scanning.
  • Do not phish or socially engineer Cyberr staff, contractors, partners or Members.
  • Do not use a finding for any purpose other than the report. No leverage, no boasting on the timeline, no pre-disclosure tipping-off of a third party, no extortion.
  • Comply with applicable law, including data-protection law and computer-misuse law in your jurisdiction and in Luxembourg.
  • Use a Cyberr Member Account only if necessary for testing, and create a dedicated research account where you can. If you use your regular Member Account, please tell us, so that any temporary anomalies on your Account are not misread as abuse.

If you are unsure whether a particular action is within scope or within these rules of engagement, ask first. We would much rather have a conversation than an awkward retrospective.

7. Safe harbour

When you act in good faith and in compliance with this CVD Policy, Cyberr commits that:

  • we will not initiate civil proceedings against you in connection with the research, the report or the coordinated disclosure;
  • we will not file a criminal complaint or otherwise refer you to law enforcement on the basis of conduct that fell within this policy;
  • if a third party initiates legal action against you in respect of conduct that fell within this policy, we will, as far as reasonably possible, make clear to that third party and, where relevant, to the authorities, that the conduct was authorised by us under this policy;
  • we treat your report as confidential, share it on a strict need-to-know basis within Cyberr and our affiliates, and do not share it with third parties beyond what is strictly necessary to remediate the issue.

This safe harbour is limited to conduct that complies with the scope (Sections 2 and 3), the reporting expectations (Section 4) and the rules of engagement (Section 6). Conduct that goes beyond those — including testing on out-of-scope assets, accessing other Members' data beyond what is strictly necessary, retaining or sharing such data, public disclosure inconsistent with Section 8, or any extortive demand — is not covered, and remains subject to the User Agreement, the Community Guidelines and applicable law.

This safe harbour is given by Cyberr SA only. We cannot, and do not, give a safe harbour for conduct that affects a third party (for example, our hosting or infrastructure providers); please respect their own policies separately.

8. Coordinated disclosure

We default to a 90-day coordination window between our acknowledgment of a confirmed vulnerability and any public disclosure. This is a starting point, not a hard rule:

  • where a fix is straightforward and we have deployed it, we are happy to coordinate earlier disclosure, including on the day of the fix;
  • where remediation requires deeper changes, supply-chain coordination or staged rollout, we may ask for a reasonable extension, which we will explain and which we will not invoke in bad faith;
  • where there is active exploitation in the wild or evidence of imminent harm, we may agree with you to disclose earlier, in a way that prioritises affected Members' ability to protect themselves.

We ask that you do not publicly disclose before the coordinated date. When you do disclose, we welcome a write-up that:

  • credits you accurately;
  • includes the CVE (we will request one where applicable), affected versions and mitigations;
  • avoids weaponised exploit code or live IOC artefacts that would not materially help defenders;
  • links to the official Cyberr advisory.

We will publish our own advisory at the coordinated date, and we will be happy to link to your write-up.

9. Recognition

At this stage, Cyberr does not operate a paid bug-bounty programme. We do, however, offer:

  • public recognition on request (for example, in the corresponding Cyberr security advisory or on our public Reputation Leaderboard page);
  • a written letter of thanks describing your contribution;
  • in serious cases, swag, conference passes or other reasonable tokens of appreciation.

If we launch a paid bounty programme in the future, we will publish its terms and the scope to which they apply. Reports submitted before the launch of such a programme will not be retroactively eligible for monetary reward, but they will continue to count for recognition purposes.

10. Confidentiality

We will treat your report as confidential, and we ask that you treat the existence of your report, the technical details of the vulnerability, and any information that you receive from us in the course of the disclosure as confidential, until the coordinated public disclosure date or until we mutually agree otherwise.

Confidentiality is not a gag: you may always speak about your work in general terms, and you may always describe the fact that you participated in this CVD process. What we ask is that you do not publish, sell or otherwise share the technical details of an unpatched vulnerability before coordination.

11. Personal data of researchers

When you submit a report, we will process the personal data you choose to provide (for example, your name, contact email and PGP key) for the purposes of triaging your report, communicating with you, remediating the issue and crediting you, where you have asked us to. Our Privacy Policy describes how we process personal data more generally.

If you wish to remain pseudonymous, please use a pseudonym and a contact channel that does not identify you. We will not attempt to identify you beyond what you have voluntarily provided.

12. Changes

We may amend this CVD Policy from time to time. The version that applies to your research is the one published at https://cyberr.ai/cvd-policy at the time you start the research; we will not apply changes retroactively to your detriment. Material changes will be announced through the Service and, where reasonably possible, we will give advance notice.

13. Contact

For all matters relating to this CVD Policy:

Email: security@cyberr.ai
PGP fingerprint: 5D51 865E E99B 6E3C B591  D8AC 6C26 7E1F FED3 9F02
Postal: Cyberr SA, 16 Rue Beck, L-1222 Luxembourg, Grand Duchy of Luxembourg, attn. Security Team.

For any other legal matter, please use the contact details in Section 15 of the User Agreement.