Responsible disclosure

Report a vulnerability

No system is perfect. If you identify a vulnerability in our systems and report it responsibly, we thank you and fix it as quickly as possible.

How to contact us

Send your report to [email protected]. We acknowledge receipt within 24 business hours and keep you informed throughout.

What to include

  • - Clear description of the vulnerability
  • - Steps to reproduce
  • - Proof of concept if available (screenshots, logs)
  • - Estimated potential impact
  • - Your contact details if you wish to be credited

Scope

Tests must remain within the scope defined below and must not affect service availability.

In scope

  • The cyberaar.io website and its subdomains
  • The aarhack.cyberaar.io platform
  • Our open source tools published under github.com/cyberaar
  • The public interfaces we operate

Out of scope

  • The AarSOC production platform and client environments
  • Third-party services and tools used by CyberAar
  • Denial-of-service attacks (DoS/DDoS)
  • Social engineering (phishing, vishing, etc.)
  • Uncoordinated tests on production systems

Handling process

01

24 business hours

Acknowledgement

We confirm receipt of your report.

02

5 business days

Assessment

Vulnerability analysis, severity and impact qualification.

03

Based on severity

Fix

A patch is deployed. You are kept informed of progress.

04

Coordinated

Disclosure

Publication coordinated with you. Credit in the Hall of Fame if you wish.

Recognition

Researchers whose report is validated are credited in our Hall of Fame with their consent. Real name or alias: the choice is theirs. Recognition is currently public and honorific.

View the Hall of Fame →

security.txt

Available at the canonical address in accordance with RFC 9116.

Contact: mailto:[email protected]
Preferred-Languages: fr, en
Canonical: https://cyberaar.io/.well-known/security.txt