Responsible Disclosure Policy
Last updated: June 2025
01Scope
This policy covers security vulnerabilities found in CipherTest-owned systems, including ciphertest.com and our internal infrastructure. It does not cover client systems, which are governed by your engagement agreement.
02Guidelines
We welcome responsible security research. To protect our systems and our users, we ask that you: test only systems you are authorized to test under this policy; avoid accessing, modifying, or destroying data that is not yours; avoid degrading service availability; and report findings promptly.
Do not exploit vulnerabilities beyond the minimum needed to demonstrate impact. Do not publicly disclose findings until we have had a reasonable opportunity to remediate.
03How to Report
Email security@ciphertest.com with a description of the vulnerability, steps to reproduce, and your assessment of impact. If possible, include a proof-of-concept and suggested remediation.
Please include a way for us to contact you and let us know how you would like to be credited (or whether you prefer to remain anonymous).
04Response
We acknowledge reports within 72 hours and provide a target remediation timeline after initial validation. We will keep you informed of progress and notify you before any public acknowledgement.
05Safe Harbor
We will not pursue legal action against researchers who make a good-faith effort to follow this policy, even if their actions would otherwise constitute a technical violation of law. We consider good faith to include the guidelines above.
06Acknowledgement
With your permission, we will acknowledge your contribution in our research hall of fame. We do not currently operate a paid bounty program.
Questions about this policy? Email contact@ciphertest.com.