Skip to content
The //Zyber// Security

Legal

Vulnerability Disclosure Policy

This policy explains how to report vulnerabilities affecting TheZyberSecurity's own systems, and what you can expect from us in return. We take security seriously and appreciate coordinated disclosure.

Last updated · 2026-07-21Reviewed by counsel: pending (owner to confirm)

1. Scope

The following properties are in scope:

  • thezybersecurity.com and its subdomains
  • Public-facing infrastructure operated by The Zyber Security
  • Mobile apps (if any) published under our name

Explicitly out of scope: client-owned assets tested under separate engagements, third-party services we merely link to, DoS testing.

2. Rules

  • Make a good-faith effort not to violate privacy, destroy data, or interrupt our services.
  • Only interact with accounts you own or with explicit permission of the account holder.
  • Do not exfiltrate more data than necessary to demonstrate the vulnerability.
  • Do not disclose the vulnerability publicly before we've had 90 days to remediate, or after we've confirmed a fix — whichever comes first.
  • Follow all applicable laws.

3. How to report

Email security@thezybersecurity.com. Encrypt with our PGP key: public.asc.

Verify the fingerprint before you trust the key. Cross-check the value below against our LinkedIn, this GitHub repo, and security.txt. If any source disagrees, do not send.

PENDING GENERATION — see docs/PGP-SETUP.md

Include in your report:

  • Vulnerability description
  • Affected asset(s) with URL / IP / component
  • Reproduction steps
  • Proof-of-concept (if safe to share)
  • Suggested severity
  • Whether you wish to be credited

4. What to expect from us

  • Acknowledgement within 2 business days.
  • Initial triage assessment within 5 business days.
  • Regular status updates until resolution.
  • Public credit in our security acknowledgements (if you wish).
  • Safe harbor: we will not pursue legal action against researchers who follow this policy in good faith.

5. Bounty

This is a coordinated-disclosure program — we do not currently pay bounties. We publicly acknowledge researchers on request, and are considering a formal bounty program for 2027.

6. Contact

Security team: security@thezybersecurity.com. See also: /.well-known/security.txt.