Last reviewed: 31 August 2026
1. Our Commitment
CyberVista Global values good-faith security research that helps protect our readers, contributors, journalists, researchers, sources, editorial systems, websites, applications, and other technology operated or controlled by CyberVista Global.
This policy explains how security researchers can report suspected vulnerabilities affecting CyberVista Global systems and the conditions under which authorized research may be treated as good-faith security testing.
This policy does not grant permission to access third-party systems, disrupt services, obtain unrelated information, compromise accounts, or violate applicable law.
When the appropriate scope is uncertain, researchers should stop testing and contact CyberVista Global through its designated security contact before proceeding.
2. Scope
In-scope assets include cybervista.global and its subdomains, applications, systems, APIs, and services that CyberVista Global expressly identifies as being operated or controlled by the organization.
Third-party hosting, analytics, payment, advertising, content-delivery, social-media, email, embedded, SaaS, cloud, and other externally operated systems are outside the scope of this policy unless CyberVista Global explicitly confirms otherwise.
If a report concerns a third-party provider but may materially affect CyberVista Global users, researchers may send CyberVista Global a minimal description of the issue.
CyberVista Global may coordinate with the relevant provider where appropriate. However, this policy does not authorize security research or testing against systems controlled by that provider.
Researchers should not assume that a third-party service is within scope merely because it is linked from or integrated into CyberVista Global.
3. Good-Faith Research Conditions
Researchers should make a genuine effort to avoid privacy violations, destruction of data, service degradation, financial harm, and access beyond what is reasonably necessary to demonstrate a suspected vulnerability.
Researchers should use the smallest practical proof of concept and the minimum level of access necessary to establish the existence and potential impact of the vulnerability.
If sensitive information is encountered unexpectedly, researchers should stop testing and must not retain, copy, publish, disclose, or share information that is unnecessary to demonstrate the vulnerability.
Researchers must not:
- Exploit a vulnerability beyond what is reasonably necessary for verification
- Establish persistence or maintain unauthorized access
- Pivot into unrelated systems
- Alter, corrupt, encrypt, or delete website or system data
- Access private editorial material beyond what is minimally necessary to establish the vulnerability
- Read confidential source communications
- Access or download databases or bulk datasets
- Perform denial-of-service, stress, destructive, or availability-impacting testing
- Send spam or excessive automated requests
- Conduct phishing or social-engineering attacks
- Test physical security without explicit authorization
- Upload malware, ransomware, malicious files, or harmful payloads
- Access, modify, or exfiltrate information belonging to other users
- Attempt to compromise employee, contributor, journalist, or source accounts
- Demand payment as a condition of withholding vulnerability information
- Threaten CyberVista Global or its users with public disclosure or exploitation
Researchers should not use vulnerabilities discovered through this process to obtain personal, financial, confidential, or otherwise unrelated information.
4. Safe-Harbor Statement
Where security research is conducted in good faith, remains within the scope of this policy, avoids unnecessary harm, and is reported promptly through CyberVista Global’s designated disclosure process, CyberVista Global will not initiate legal action solely because the researcher performed activity authorized by this policy.
If a third party initiates action and the research complied with this policy, CyberVista Global may, where appropriate and lawful, clarify that the activity was conducted as part of its vulnerability disclosure process.
This safe harbor does not bind third parties, regulators, law-enforcement authorities, service providers, or other entities that may have independent rights or obligations.
The safe harbor does not protect malicious, extortionate, reckless, deliberately harmful, fraudulent, out-of-scope, or otherwise unlawful conduct.
CyberVista Global reserves the right to take appropriate action where activity creates significant risk to users, systems, confidential information, availability, or third-party infrastructure.
5. How to Report
Security reports should be submitted through CyberVista Global’s designated security contact or vulnerability-reporting channel.
Where a dedicated security email address is provided by CyberVista Global, researchers should use that address and, where possible, use the subject line:
Security vulnerability report
A report should, where possible, include:
- The affected URL, application, API, system, or asset
- The type and severity of the suspected vulnerability
- Clear steps required to reproduce the issue
- Observed and potential security impact
- Date and approximate time of testing
- Relevant browser, operating system, tool, or testing environment information
- A proof of concept that minimizes exposure
- Relevant request and response information where necessary
- Any suggested remediation or mitigation
Researchers should not attach large databases, private messages, identity documents, passwords, credentials, authentication tokens, private keys, or unnecessary personal information.
If sensitive evidence is necessary, researchers should request an appropriate encrypted communication channel before transmitting it.
CyberVista Global should maintain a valid /.well-known/security.txt file identifying its current security contact, policy URL, preferred language, and relevant expiry information.
6. Response Targets
CyberVista Global aims to:
- Acknowledge credible security reports within three business days
- Provide an initial assessment within ten business days
- Communicate material status changes while remediation is underway
- Coordinate disclosure timelines with the reporting researcher where appropriate
These are response targets rather than guarantees.
Complex vulnerabilities, third-party dependencies, holidays, active security incidents, infrastructure limitations, incomplete reports, or other circumstances may require additional time.
Vulnerabilities may be prioritized according to factors including:
- Exploitability
- Affected data
- Potential user impact
- Required privileges
- Affected systems or scope
- Persistence
- Availability of mitigations
- Likelihood of exploitation
- Potential confidentiality, integrity, or availability impact
A researcher should not assume that failure to receive an immediate response means that a report has been rejected or ignored.
7. Coordinated Disclosure
Researchers should allow CyberVista Global a reasonable period to assess and remediate a reported vulnerability before publicly disclosing it.
CyberVista Global will seek to discuss an appropriate disclosure timeline with the researcher in good faith.
Researchers should avoid public disclosure of:
- Exploit credentials
- Authentication tokens
- Private information
- Confidential source information
- Unpatched exploit details that materially increase risk
- Internal security configurations
- Information that could facilitate further exploitation
Immediate public disclosure may be justified in exceptional circumstances, including situations involving active exploitation or substantial and ongoing risk to users. Researchers are encouraged to communicate such circumstances clearly when reporting the vulnerability.
CyberVista Global may credit a researcher publicly with their consent after remediation or at another mutually agreed stage.
CyberVista Global does not promise payment, a bug bounty, employment, public recognition, or other compensation unless such terms have been expressly agreed in writing before the report or research activity.
8. Out-of-Scope Findings
The following are generally outside the scope of this disclosure process unless they demonstrate a meaningful security impact:
- Missing security headers without demonstrated exploitability
- Clickjacking on pages without sensitive actions
- Self-XSS
- Rate-limit observations without meaningful exploitation or security impact
- Automated scanner results without manual validation
- Username or account enumeration without additional security impact
- Email authentication observations without evidence of exploitability
- Informational software-version disclosures without demonstrated security impact
- Vulnerabilities existing solely within unsupported third-party components not controlled by CyberVista Global
- Best-practice recommendations without a demonstrated vulnerability
- Reports concerning services or infrastructure outside CyberVista Global’s control
An issue being classified as out of scope does not necessarily mean that it has no security value.
CyberVista Global may still review an out-of-scope finding where the evidence indicates a credible risk to users, systems, confidential information, or the security of CyberVista Global’s services.
9. Incident and Privacy Handling
Security reports may be shared only with CyberVista Global personnel, service providers, professional advisers, or other parties who reasonably need the information for security assessment, remediation, legal compliance, insurance, incident response, or related legitimate purposes.
Security records may be retained for security, accountability, audit, compliance, incident-response, and legal purposes.
Personal information contained in a security report should be minimized and handled in accordance with CyberVista Global’s Privacy Policy and applicable data-protection requirements.
Researchers should avoid including unnecessary personal, confidential, proprietary, or sensitive information in vulnerability reports.
Where a report involves personal data, confidential sources, credentials, or other highly sensitive information, CyberVista Global may apply additional access restrictions and security controls.
If CyberVista Global determines that a reported vulnerability has resulted in unauthorized access, disclosure, or other material security impact, it may initiate its applicable incident-response procedures.
10. Contact
Security vulnerabilities:
Please use CyberVista Global’s designated security contact or vulnerability-reporting channel.
Privacy concerns unrelated to a security vulnerability:
Please use CyberVista Global’s designated privacy contact channel.
Editorial safety or source-security concerns:
Please use CyberVista Global’s designated editorial or contact channel.
For security vulnerabilities, researchers should use the dedicated security-reporting channel wherever possible so that reports reach the appropriate responsible function promptly.
CyberVista Global may update its security contact information and reporting mechanisms as its infrastructure and security operations develop.
Last reviewed: 31 August 2026.
