Security

Vulnerability disclosure

Effective from: 1 August 2026 · Contact: security (at) cybbrio.cz · security.txt

We are a security company, so we take reports seriously and we answer them. If you have found a vulnerability in our website or services, let us know.

How to report

Write to security (at) cybbrio.cz, ideally encrypted with our PGP key. Include a description, reproduction steps, impact and optionally a proof of concept. Czech or English is fine.

Response times

In scope

The cybbrio.cz domain, its subdomains and services we operate. Client systems are out of scope - testing them without a contract is illegal.

What you must not do

Safe harbour

If you report in good faith and follow these rules, we will not pursue legal action against you and we will work with you on remediation. We are happy to credit you if you wish.

Rewards

We do not run a paid bug bounty programme. For a good report we offer thanks, feedback and coordinated disclosure.