Scope
This policy covers cypherslash.com and its subdomains, along with the products we publicly operate. If you are not sure whether something belongs to us, ask first at [email protected] and we will tell you straight.
How to report
Email [email protected] with what you found, where you found it, the steps to reproduce it, and the impact as you see it. A short proof of concept is welcome. Screenshots and request logs help us move faster. Please give us reasonable time to fix the issue before any public disclosure.
What to expect from us
- An acknowledgement within three business days.
- Honest updates while we investigate and fix, not silence.
- Credit by your name or handle once the fix ships, if you want it. Quiet, if you prefer that instead.
We do not run a paid bounty program yet. What we offer is a fast response, a straight conversation, and public thanks from a team that knows exactly how much skill a good finding takes.
Ground rules
Good faith research is welcome here. Act within these rules and we will not pursue legal action against you:
- Do not access, change, or delete data that is not yours. Use your own test accounts.
- No denial of service, no traffic floods, no resource exhaustion.
- No spam, no phishing, and no social engineering of our people or partners.
- No physical attempts against offices, hardware, or infrastructure.
- Stop as soon as you can demonstrate the impact, then report it. Do not dig further to see how deep it goes.
Out of scope
- Findings on third party services we merely link to. Report those to their owners.
- Missing best practice headers or configuration notes without a demonstrated impact.
- Raw automated scanner output that has not been validated by hand.
- Clickjacking on pages that carry no sensitive action.
This policy follows the spirit of RFC 9116. A machine readable version lives at /.well-known/security.txt.