Community
Building security together
Security is a collective endeavour: no one holds all the answers alone.
We open our work, recognise those who help us improve our systems, and are building spaces to train and connect.
Responsible disclosure programme
No system is perfect. If you identify a vulnerability in our own systems and report it responsibly, we publicly acknowledge your contribution and remediate as quickly as possible.
In scope
- ✓ The cyberaar.io website and its subdomains
- ✓ Our open-source tooling and published components
- ✓ The public interfaces we operate
Out of scope
- ✕ The AarSOC production platform and client environments
- ✕ Third-party services and tools used by CyberAar
- ✕ Denial-of-service attacks
- ✕ Social engineering (phishing, vishing, etc.)
Recognition
Researchers whose reports are validated are credited in our Hall of Fame with their consent. Real name or alias: the choice is theirs.
Recognition is currently public and honorary. A reward programme may be introduced at a later stage.
Hall of Fame
Researchers whose contribution has been validated and who have consented to being credited appear here. No exploitable technical detail is published, even for vulnerabilities that have been remediated.
Training
Training the next generation
In preparationWe are preparing an open learning space, designed so that understanding comes before validation — to support those who are starting out in cybersecurity. Not a simple quiz: a progression that verifies comprehension.
Articles & write-ups
Analyses, experience reports and write-ups will be published here as our work progresses.
Our disclosure programme, our open-source work and, in time, our bug bounty platform form a single space: bringing together those who push security forward.