Home
Security

Responsible Disclosure Policy

Scope, safe harbour, how to report a vulnerability in Cyber VK itself, and the response times you can hold us to.

Effective from
Last updated

Why this page exists

A platform that teaches offensive security and has no disclosure policy is telling its own audience that the rules apply to them and not to us. This is the route we want a researcher to take, and it is monitored by the people who can fix what you find.

In scope

  • The Cyber VK web application and its API.
  • Authentication, session handling, and the entitlement and quota gates.
  • The billing and subscription flow, excluding the payment provider systems, which have their own programme.
  • The lab orchestration control plane, meaning anything that lets a session escape its own boundary or affect another learner.

Out of scope

  • The deliberately vulnerable sandbox targets themselves. They are supposed to be vulnerable. A finding inside your own sandbox is the exercise working correctly.
  • Denial of service, volumetric testing, and anything that degrades the service for other learners. Do not test rate limits by exhausting them.
  • Social engineering of staff, learners or support, and physical attacks of any kind.
  • Reports from automated scanners with no demonstrated impact, missing hardening headers with no exploit path, and best-practice observations. These are welcome as feedback and are not vulnerabilities.

Rules of engagement

  1. Use your own account and your own test data. If a proof of concept needs a second account, register one and say so in the report.
  2. Stop at proof. Read one record, not the table. Confirm the primitive and do not pivot with it.
  3. Do not access, modify or delete another person data. If you encounter it by accident, stop, do not save it, and tell us in the report.
  4. Give us a reasonable period to fix the issue before publishing. 90 days is the default and we will usually be much faster; if you have a reason to need a different timeline, say so and we will agree one.

How to report

Email [email protected]. A machine-readable version of this contact is published at /.well-known/security.txt as required by RFC 9116. Include what you found, where, the steps to reproduce it, and what an attacker could do with it. A single clear reproduction is worth more than a long report.

What you can expect from us

Our commitments and the time we hold ourselves to.
StageTarget
Acknowledgement that a human has read it1 business day
Triage decision, with the severity we assigned and why3 business days
Fix for a critical or high finding14 days
Fix for a medium or low finding90 days
Confirmation that the fix is live, and your credit if you want oneOn deploy
Our commitments and the time we hold ourselves to.

We will tell you what we decided and why, including when we disagree with your severity assessment. A researcher who is told nothing has no reason to come back, and we would rather argue about a CVSS score than lose the report.

Rewards

Cyber VK does not currently operate a paid bug bounty programme. A valid report can be credited publicly with the researcher’s consent. Please do not undertake testing that creates cost, affects another person, accesses unnecessary data, or assumes a payment will be offered.

Contact

Where to send it

Security contact

[email protected]

The machine-readable version of this contact is published at /.well-known/security.txt per RFC 9116. If the two ever disagree, the file is authoritative and this page is the bug.

What we publish about live vulnerabilitiesThe acceptable use policy

Responsible Disclosure Policy · Cyber VK