1. Scope
The following properties are in scope:
thezybersecurity.comand its subdomains- Public-facing infrastructure operated by The Zyber Security
- Mobile apps (if any) published under our name
Explicitly out of scope: client-owned assets tested under separate engagements, third-party services we merely link to, DoS testing.
2. Rules
- Make a good-faith effort not to violate privacy, destroy data, or interrupt our services.
- Only interact with accounts you own or with explicit permission of the account holder.
- Do not exfiltrate more data than necessary to demonstrate the vulnerability.
- Do not disclose the vulnerability publicly before we've had 90 days to remediate, or after we've confirmed a fix — whichever comes first.
- Follow all applicable laws.
3. How to report
Email security@thezybersecurity.com. Encrypt with our PGP key: public.asc.
Verify the fingerprint before you trust the key. Cross-check the value below against our LinkedIn, this GitHub repo, and security.txt. If any source disagrees, do not send.
PENDING GENERATION — see docs/PGP-SETUP.mdInclude in your report:
- Vulnerability description
- Affected asset(s) with URL / IP / component
- Reproduction steps
- Proof-of-concept (if safe to share)
- Suggested severity
- Whether you wish to be credited
4. What to expect from us
- Acknowledgement within 2 business days.
- Initial triage assessment within 5 business days.
- Regular status updates until resolution.
- Public credit in our security acknowledgements (if you wish).
- Safe harbor: we will not pursue legal action against researchers who follow this policy in good faith.
5. Bounty
This is a coordinated-disclosure program — we do not currently pay bounties. We publicly acknowledge researchers on request, and are considering a formal bounty program for 2027.
6. Contact
Security team: security@thezybersecurity.com. See also: /.well-known/security.txt.