Responsible Disclosure Policy
CyberEDT values the cybersecurity community and believes that responsible security research plays an essential role in improving the security of our platforms, services, and users.
We encourage security researchers, ethical hackers, students, and professionals to responsibly disclose vulnerabilities they discover in CyberEDT systems.
Our goal is to establish an open, transparent, and collaborative vulnerability disclosure process that enables security issues to be identified, verified, and resolved responsibly.
Safe Harbor Statement
If you conduct security research in good faith and follow this Responsible Disclosure Policy, CyberEDT considers your activities to be authorized.
CyberEDT will not initiate legal action against researchers who:
- Act responsibly and ethically
- Avoid violating user privacy
- Do not intentionally disrupt services
- Report vulnerabilities privately
- Provide reasonable time for remediation before public disclosure
If a third party initiates legal action related to your research, CyberEDT will make it known that your activities were conducted in accordance with this policy.
Reporting Process
Step 1 — Discover
Identify a potential security vulnerability within the CyberEDT ecosystem.
Step 2 — Report
Submit your findings through our responsible disclosure channel.
Step 3 — Validation
Our security team reviews, verifies, and prioritizes the reported issue.
Step 4 — Remediation
Our engineering team develops, tests, and deploys a fix.
Step 5 — Recognition
Researchers who make meaningful contributions may receive acknowledgment in the CyberEDT Security Hall of Fame.
Scope
The following CyberEDT assets are currently in scope.
Main Platform
- www.cyberedt.com
- *.cyberedt.com
Products
- CyberEDT Tools
- ETH (Explain The Hacker)
- EME (Explain My Exposure)
- ETD (Explain The Defender)
- CyberEDT Intelligence Layer (CIL)
APIs
- API Endpoints
- Authentication Systems
- Authorization Mechanisms
- Public Services
Security Areas
- Authentication
- Authorization
- Session Management
- Access Control
- Information Disclosure
- Business Logic Vulnerabilities
- API Security
- Cloud Misconfigurations
Out of Scope
The following activities are outside this disclosure program.
- Distributed Denial of Service (DDoS)
- Physical attacks
- Social engineering against CyberEDT personnel
- Spam
- Automated vulnerability scans causing service disruption
- Third-party vulnerabilities without a working proof of concept
- Clickjacking without sensitive impact
- Self-XSS
- Issues requiring unrealistic attack conditions
Submission Requirements
Please include the following information when submitting a report.
Vulnerability Description
Clearly explain the issue and its potential impact.
Steps to Reproduce
Provide detailed reproduction steps or a Proof of Concept (PoC).
Environment
Include:
- Browser
- Operating System
- Device
- Product
- Endpoint
- Version (if applicable)
Impact Assessment
Explain what an attacker could accomplish.
Suggested Remediation (Optional)
Recommendations are welcome but not required.
Severity Classification
Critical
Target Response: Within 24 Hours
Examples:
- Remote Code Execution (RCE)
- Authentication Bypass
- SQL Injection
- Complete Data Exposure
- Critical Cloud Misconfiguration
High
Target Response: Within 48 Hours
Examples:
- Stored XSS
- SSRF
- Privilege Escalation
- Sensitive Information Disclosure
Medium
Target Response: Within 3 Business Days
Examples:
- Reflected XSS
- CSRF
- IDOR
- Directory Traversal
- Insecure API Configuration
Low
Target Response: Within 5 Business Days
Examples:
- Open Redirect
- Missing Security Headers
- Minor Information Disclosure
- Best Practice Recommendations
Research Guidelines
Researchers are expected to:
- Respect user privacy
- Avoid accessing unnecessary data
- Stop testing immediately after confirming a vulnerability
- Never modify or destroy production data
- Avoid disrupting CyberEDT services
- Keep vulnerabilities confidential until remediation is complete
Recognition
CyberEDT appreciates responsible security research.
Researchers may be recognized through:
- CyberEDT Security Hall of Fame
- Public Acknowledgment (with permission)
- Certificates of Appreciation
- Community Recognition
- Future Bug Bounty Invitations (if introduced)
Recognition is awarded at CyberEDT's discretion based on the quality and impact of the report.
What We Ask From You
Please allow our security team reasonable time to investigate and resolve reported vulnerabilities before publicly disclosing technical details.
Responsible disclosure helps protect the CyberEDT community and its users.
Contact the Security Team
To report a vulnerability or contact our security team:
Security Team
📧 founder@cyberedt.com
For encrypted communications, a PGP public key is available upon request.
Our Commitment
CyberEDT is committed to fostering a culture of responsible security, transparency, and continuous improvement.
Every responsible disclosure strengthens our platform and helps build a safer cybersecurity ecosystem for learners, professionals, organizations, and the global security community.