Skip to main content
RFC 9116 COMPLIANT SECURITY POLICY

Responsible Vulnerability Disclosure

Cyravex Security values the cybersecurity community's role in helping us maintain the security and privacy of our web infrastructure. If you believe you have discovered a vulnerability in a Cyravex asset, we encourage you to report it to us promptly.

Reporting Email

Please send encrypted reports to: security@cyravex.com

Canonical security.txt available at: https://cyravex.com/.well-known/security.txt

Authorized Scope

  • Primary domain: cyravex.com
  • All subdomains directly owned by Cyravex Security

Out of Scope

  • Volumetric Denial of Service (DoS / DDoS)
  • Social engineering or phishing targeting Cyravex staff
  • Physical attacks against facilities or hardware
  • Vulnerabilities in third-party services not under Cyravex control

Our Commitment

If you follow these guidelines in good faith:

  • We will acknowledge receipt of your report within 48 hours.
  • We will not pursue legal action against researchers acting in accordance with this policy.
  • We will notify you when the reported vulnerability is remediated.