Last updated: 10 July 2026
At CYVORA, we take the security of our systems and services seriously. We appreciate the efforts of security researchers and the wider community in helping us identify potential vulnerabilities. This Responsible Disclosure Policy outlines how to report security issues to us and what you can expect in return.
Report To
security@cyvorasecurity.comResponse Time
Within 48 hours
Safe Harbour
Good-faith reporting protected
This policy applies to vulnerabilities found in:
Vulnerabilities in third-party services or in client environments should be reported to the respective owner, not to CYVORA.
To help us address reports effectively, we ask that you:
We will not pursue legal action against individuals who report vulnerabilities in good faith, in accordance with this policy, and who do not cause harm to CYVORA, our clients or third parties. We consider good-faith research to be a valuable contribution to security.
The following are not considered vulnerabilities under this policy:
Please include in your report: a description of the vulnerability, the affected asset, steps to reproduce, potential impact, and any suggested remediation. Send all reports to security@cyvorasecurity.com.
If you believe a vulnerability may affect a client engagement or active incident response, please flag this clearly in your report so we can prioritise accordingly.
© 2026 CYVORA. All rights reserved.