Responsible Disclosure Policy
Scope, safe harbour, how to report a vulnerability in Cyber VK itself, and the response times you can hold us to.
- Effective from
- Last updated
Why this page exists
A platform that teaches offensive security and has no disclosure policy is telling its own audience that the rules apply to them and not to us. This is the route we want a researcher to take, and it is monitored by the people who can fix what you find.
In scope
- The Cyber VK web application and its API.
- Authentication, session handling, and the entitlement and quota gates.
- The billing and subscription flow, excluding the payment provider systems, which have their own programme.
- The lab orchestration control plane, meaning anything that lets a session escape its own boundary or affect another learner.
Out of scope
- The deliberately vulnerable sandbox targets themselves. They are supposed to be vulnerable. A finding inside your own sandbox is the exercise working correctly.
- Denial of service, volumetric testing, and anything that degrades the service for other learners. Do not test rate limits by exhausting them.
- Social engineering of staff, learners or support, and physical attacks of any kind.
- Reports from automated scanners with no demonstrated impact, missing hardening headers with no exploit path, and best-practice observations. These are welcome as feedback and are not vulnerabilities.
Rules of engagement
- Use your own account and your own test data. If a proof of concept needs a second account, register one and say so in the report.
- Stop at proof. Read one record, not the table. Confirm the primitive and do not pivot with it.
- Do not access, modify or delete another person data. If you encounter it by accident, stop, do not save it, and tell us in the report.
- Give us a reasonable period to fix the issue before publishing. 90 days is the default and we will usually be much faster; if you have a reason to need a different timeline, say so and we will agree one.
How to report
Email [email protected]. A machine-readable version of this contact is published at /.well-known/security.txt as required by RFC 9116. Include what you found, where, the steps to reproduce it, and what an attacker could do with it. A single clear reproduction is worth more than a long report.
What you can expect from us
| Stage | Target |
|---|---|
| Acknowledgement that a human has read it | 1 business day |
| Triage decision, with the severity we assigned and why | 3 business days |
| Fix for a critical or high finding | 14 days |
| Fix for a medium or low finding | 90 days |
| Confirmation that the fix is live, and your credit if you want one | On deploy |
We will tell you what we decided and why, including when we disagree with your severity assessment. A researcher who is told nothing has no reason to come back, and we would rather argue about a CVSS score than lose the report.
Rewards
Cyber VK does not currently operate a paid bug bounty programme. A valid report can be credited publicly with the researcher’s consent. Please do not undertake testing that creates cost, affects another person, accesses unnecessary data, or assumes a payment will be offered.
Where to send it
Security contact
The machine-readable version of this contact is published at /.well-known/security.txt per RFC 9116. If the two ever disagree, the file is authoritative and this page is the bug.
What we publish about live vulnerabilitiesThe acceptable use policy