Legal

Responsible Disclosure Policy

Last updated: 10 July 2026

At CYVORA, we take the security of our systems and services seriously. We appreciate the efforts of security researchers and the wider community in helping us identify potential vulnerabilities. This Responsible Disclosure Policy outlines how to report security issues to us and what you can expect in return.

Response Time

Within 48 hours

Safe Harbour

Good-faith reporting protected

1. Scope

This policy applies to vulnerabilities found in:

  • The CYVORA website and any web applications we operate.
  • Infrastructure directly controlled by CYVORA.
  • Services and platforms we use to deliver cybersecurity engagements to clients.

Vulnerabilities in third-party services or in client environments should be reported to the respective owner, not to CYVORA.

2. What We Ask of You

To help us address reports effectively, we ask that you:

  • Report vulnerabilities promptly to security@cyvorasecurity.com.
  • Provide enough detail to reproduce and understand the issue, including steps and, if possible, proof of concept.
  • Avoid accessing, modifying or destroying data that does not belong to you.
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it.
  • Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it.
  • Act in good faith and respect the privacy of others.

3. What You Can Expect From Us

  • Acknowledgement of your report within 48 hours.
  • A preliminary assessment and a timeline for remediation where applicable.
  • Clear communication throughout the remediation process.
  • Recognition of your contribution, where you wish to be credited, once the issue is resolved.

4. Safe Harbour

We will not pursue legal action against individuals who report vulnerabilities in good faith, in accordance with this policy, and who do not cause harm to CYVORA, our clients or third parties. We consider good-faith research to be a valuable contribution to security.

5. Out of Scope

The following are not considered vulnerabilities under this policy:

  • Denial of service or volumetric attacks against our infrastructure.
  • Social engineering of CYVORA staff or clients.
  • Physical attacks or attempts to access physical premises.
  • Vulnerabilities in third-party applications already reported to the vendor.
  • Issues requiring no technical exploitation, such as clickjacking on non-sensitive pages.

6. Reporting a Vulnerability

Please include in your report: a description of the vulnerability, the affected asset, steps to reproduce, potential impact, and any suggested remediation. Send all reports to security@cyvorasecurity.com.

If you believe a vulnerability may affect a client engagement or active incident response, please flag this clearly in your report so we can prioritise accordingly.

© 2026 CYVORA. All rights reserved.