Responsible disclosure
Report a vulnerability
No system is perfect. If you identify a vulnerability in our systems and report it responsibly, we thank you and fix it as quickly as possible.
How to contact us
Send your report to [email protected]. We acknowledge receipt within 24 business hours and keep you informed throughout.
What to include
- - Clear description of the vulnerability
- - Steps to reproduce
- - Proof of concept if available (screenshots, logs)
- - Estimated potential impact
- - Your contact details if you wish to be credited
Scope
Tests must remain within the scope defined below and must not affect service availability.
In scope
- ✓ The cyberaar.io website and its subdomains
- ✓ The aarhack.cyberaar.io platform
- ✓ Our open source tools published under github.com/cyberaar
- ✓ The public interfaces we operate
Out of scope
- ✕ The AarSOC production platform and client environments
- ✕ Third-party services and tools used by CyberAar
- ✕ Denial-of-service attacks (DoS/DDoS)
- ✕ Social engineering (phishing, vishing, etc.)
- ✕ Uncoordinated tests on production systems
Handling process
24 business hours
Acknowledgement
We confirm receipt of your report.
5 business days
Assessment
Vulnerability analysis, severity and impact qualification.
Based on severity
Fix
A patch is deployed. You are kept informed of progress.
Coordinated
Disclosure
Publication coordinated with you. Credit in the Hall of Fame if you wish.
Recognition
Researchers whose report is validated are credited in our Hall of Fame with their consent. Real name or alias: the choice is theirs. Recognition is currently public and honorific.
View the Hall of Fame →security.txt
Available at the canonical address in accordance with RFC 9116.
Contact: mailto:[email protected] Preferred-Languages: fr, en Canonical: https://cyberaar.io/.well-known/security.txt