Vulnerability Disclosure Policy

  • Effective Date: June 23, 2026
  • Last Updated: June 23, 2026

CipherGap welcomes good-faith security research.

This Vulnerability Disclosure Policy explains how to report suspected vulnerabilities in CipherGap systems and what activity is authorized.

1. Scope

This policy applies to publicly accessible CipherGap-owned systems and services, including:

  • https://ciphergap.com
  • https://www.ciphergap.com
  • CipherGap web application endpoints.
  • CipherGap API endpoints, if publicly documented.

This policy does not authorize testing of:

  • Third-party services not owned by CipherGap.
  • Customer scan targets.
  • Customer systems.
  • Cloud provider infrastructure not controlled by CipherGap.
  • Social engineering.
  • Physical attacks.
  • Employee devices.
  • Vendor systems.
  • Denial-of-service testing.

2. Safe Harbor

If you make a good-faith effort to comply with this policy, we will not pursue legal action against you for research activities that are authorized by this policy.

To qualify for safe harbor, you must:

  • Stay within the defined scope.
  • Avoid privacy violations.
  • Avoid service disruption.
  • Avoid data destruction.
  • Avoid extortion or threats.
  • Report vulnerabilities promptly.
  • Give us reasonable time to investigate and remediate.
  • Not publicly disclose the issue until we have resolved it or given written permission.

This policy does not bind third parties.

3. Authorized Research

The following activities are generally authorized if performed safely and within scope:

  • Testing for common web application vulnerabilities.
  • Testing authentication and authorization logic using accounts you own.
  • Testing account isolation using accounts you control.
  • Reviewing publicly exposed metadata.
  • Reporting misconfigurations.
  • Reporting vulnerable dependencies when exploitability is demonstrated.
  • Reporting cryptographic implementation issues.
  • Reporting access-control weaknesses.

4. Prohibited Activity

Do not perform:

  • Denial-of-service or stress testing.
  • Spam or phishing.
  • Social engineering.
  • Physical attacks.
  • Malware deployment.
  • Credential stuffing.
  • Brute-force attacks.
  • Destructive testing.
  • Data exfiltration.
  • Persistence.
  • Lateral movement.
  • Testing against customer scan targets.
  • Testing against third-party infrastructure.
  • Public disclosure before remediation.
  • Accessing, modifying, or deleting data that is not yours.

If you accidentally access data that is not yours, stop immediately, do not save or share the data, and report the issue.

5. Reporting a Vulnerability

Send reports to:

security@ciphergap.com

Please include:

  • A clear description of the issue.
  • Affected URL, endpoint, or feature.
  • Steps to reproduce.
  • Impact assessment.
  • Screenshots or proof of concept, if safe.
  • Your contact information.
  • Whether you accessed any data that was not yours.
  • Any suggested remediation.

Do not include sensitive customer data in your report.

6. What to Expect

After receiving a report, we aim to:

  • Acknowledge receipt within 3 business days.
  • Triage the issue.
  • Request clarification if needed.
  • Validate impact.
  • Remediate based on severity and risk.
  • Notify you when the issue has been addressed, where appropriate.

We do not currently operate a paid bug bounty program.

Submission of a report does not guarantee compensation.

7. Severity and Prioritization

We prioritize vulnerabilities based on:

  • Exploitability.
  • Authentication requirements.
  • Data exposure.
  • Customer impact.
  • System impact.
  • Availability impact.
  • Scope.
  • Remediation complexity.

Critical issues affecting account access, customer data isolation, authentication, authorization, or production infrastructure will generally receive higher priority.

8. Public Disclosure

Do not publicly disclose a vulnerability until we have completed remediation and given written permission.

We support coordinated disclosure and will work with researchers in good faith.

9. Out-of-Scope Findings

The following are generally out of scope unless they create a clearly exploitable security impact:

  • Missing security headers without demonstrated impact.
  • Clickjacking on pages with no sensitive action.
  • SPF, DKIM, or DMARC findings without demonstrated abuse risk.
  • TLS configuration preferences without exploitability.
  • Rate-limit observations without practical attack impact.
  • Self-XSS.
  • Reports from automated scanners without validation.
  • Username or email enumeration without demonstrated impact.
  • Logout CSRF.
  • Issues requiring physical access.
  • Issues requiring malware on the victim device.
  • Theoretical vulnerabilities without a working proof of concept.

10. Contact

  • Security reports: security@ciphergap.com
  • General support: support@ciphergap.com
  • Abuse reports: abuse@ciphergap.com