Community

Building security together

Security is a collective endeavour: no one holds all the answers alone.

We open our work, recognise those who help us improve our systems, and are building spaces to train and connect.

Responsible disclosure programme

No system is perfect. If you identify a vulnerability in our own systems and report it responsibly, we publicly acknowledge your contribution and remediate as quickly as possible.

In scope

  • The cyberaar.io website and its subdomains
  • Our open-source tooling and published components
  • The public interfaces we operate

Out of scope

  • The AarSOC production platform and client environments
  • Third-party services and tools used by CyberAar
  • Denial-of-service attacks
  • Social engineering (phishing, vishing, etc.)

Recognition

Researchers whose reports are validated are credited in our Hall of Fame with their consent. Real name or alias: the choice is theirs.

Recognition is currently public and honorary. A reward programme may be introduced at a later stage.

Report a vulnerability

Hall of Fame

Researchers whose contribution has been validated and who have consented to being credited appear here. No exploitable technical detail is published, even for vulnerabilities that have been remediated.

Researcher Date Category

The first contributors will appear here.
Will you be the first?

Report a vulnerability →

Training

Training the next generation

In preparation

We are preparing an open learning space, designed so that understanding comes before validation — to support those who are starting out in cybersecurity. Not a simple quiz: a progression that verifies comprehension.

Articles & write-ups

Analyses, experience reports and write-ups will be published here as our work progresses.

Our disclosure programme, our open-source work and, in time, our bug bounty platform form a single space: bringing together those who push security forward.