Security
Responsible Disclosure
Good-faith researchers may report vulnerabilities in CYBRION. This is not a public bug bounty and does not authorise testing that harms customers.
How to report
Email support@cybot-x.com with subject line “Security disclosure”, a clear description, impact, and steps to reproduce. Include only the minimum data needed. Do not access other tenants’ data, exfiltrate content, or disrupt production.
Out of scope
- Social engineering of CYBOT-X staff or customers
- Denial-of-service or volumetric attacks
- Physical security, spam, or third-party services we do not control
- Findings that require privileged insider access you already have
Our response
We aim to acknowledge within five (5) business days. Remediation timing is at our sole discretion. Public disclosure is allowed only after we confirm a fix in writing. We may decline to engage with reports that violate these rules or applicable law.
No licence to copy
Security research does not grant rights to our source code, architecture, or proprietary detection logic. Publishing exploit details that enable abuse of customer environments is prohibited.