Skip to main content
VULNERABILITY COORDINATION // RFC 9116

Responsible Disclosure Policy

CySLex builds its business on finding and fixing security weaknesses. We welcome the same scrutiny of our own systems. If you believe you have found a vulnerability in a CySLex asset, we want to hear from you, and we commit to working with you in good faith.

SECTION 01

Scope

In scope
  • cyslex.com and all subdomains operated by CySLex (*.cyslex.com)
  • Public APIs and web services hosted on those domains
  • CySLex-published software and tools, where we identify them as ours
Out of scope
  • Systems, domains, or services belonging to our clients. Never test a CySLex client environment under this policy; if you find something there, contact that organization directly.
  • Third-party services we use (hosting, email, CDN, anti-bot providers). Report those to the respective vendor.
  • Findings that require physical access, social engineering of CySLex personnel, or stolen credentials.
  • Denial-of-service, resource exhaustion, or volumetric testing.
  • Automated scanning that generates significant traffic or degrades service.
  • Reports of missing best-practice headers, SPF/DMARC configuration, version banners, or clickjacking on pages without sensitive actions, unless combined into a demonstrable exploit.
  • Self-XSS, CSRF on logout, or issues in unsupported browsers.
SECTION 02

How to Report

Email security@cyslex.com. Please include:

The affected URL, endpoint, or component
A clear description of the issue and its impact
Step-by-step reproduction instructions, with request/response samples or a proof of concept where possible
Your name or handle, if you would like credit
Have a technical finding to submit?
SECTION 03

What We Ask of You

Act in good faith to avoid privacy violations, data destruction, and disruption of service.
Access, download, or modify only the minimum data needed to demonstrate the issue; if you encounter personal or client data, stop and report immediately.
Do not exploit the finding beyond proof of concept, and do not use it to pivot to other systems.
Give us reasonable time to remediate before any public disclosure (see Section 5).
Do not demand payment as a condition of disclosure.
SECTION 04

What You Can Expect from Us

Acknowledgment of your report within 3 business days.
Initial assessment and severity rating within 10 business days.
Regular status updates while we remediate, and a notification when the fix is deployed.
Credit on this page for valid, previously unknown findings, if you wish.
Safe Harbor: CySLex will not pursue civil action or refer to law enforcement any security research conducted in accordance with this policy. We consider such research authorized under applicable computer-misuse laws, including the U.S. Computer Fraud and Abuse Act (CFAA), to the extent of our authority. If a third party initiates legal action against you for research conducted under this policy, we will make it known that your actions were authorized.
SECTION 05

Coordinated Disclosure Timeline

We ask for 90 days from acknowledgment before public disclosure. If remediation requires longer, we will explain why and agree on a revised date with you. If we fix the issue sooner, you are free to publish once we confirm the fix is live. We will coordinate any public statement with you and credit you as agreed.
SECTION 06

Severity Guidance

We triage using CVSS v4.0 as a baseline and adjust for real-world impact to CySLex and its clients. Examples of what we consider high or critical: remote code execution (RCE), authentication bypass, access to client engagement data, server-side request forgery (SSRF) reaching internal services, and injection with demonstrable data access.
SECTION 07

Recognition

Researchers who have responsibly reported valid vulnerabilities will be listed here with their consent.
Hall of Fame

No entries yet.