Security
Vulnerability disclosure
We are a security company, so we take reports seriously and we answer them. If you have found a vulnerability in our website or services, let us know.
How to report
Write to security (at) cybbrio.cz, ideally encrypted with our PGP key. Include a description, reproduction steps, impact and optionally a proof of concept. Czech or English is fine.
Response times
- Acknowledgement within 3 business days.
- Initial assessment and our position within 10 business days.
- Progress updates on remediation; critical findings are handled immediately.
In scope
The cybbrio.cz domain, its subdomains and services we operate. Client systems are out of scope - testing them without a contract is illegal.
What you must not do
- Actions causing service disruption, deletion or modification of data.
- Accessing personal data beyond what is strictly necessary to demonstrate the vulnerability; do not copy or retain any data you find.
- Social engineering against our people, phishing, physical attacks and spam.
- Publishing the finding before a coordinated disclosure date is agreed.
Safe harbour
If you report in good faith and follow these rules, we will not pursue legal action against you and we will work with you on remediation. We are happy to credit you if you wish.
Rewards
We do not run a paid bug bounty programme. For a good report we offer thanks, feedback and coordinated disclosure.