Responsible Disclosure Policy

Last updated: to be completed

Content to be reviewed by a lawyer before production. This text is a working template and has no contractual value as it stands.

Our commitment

We welcome reports of vulnerabilities affecting our own services (the CYBERDUR site, application and infrastructure).

How to report

Send your report to security@cyberdur.fr with a description, reproduction steps and, if possible, an impact assessment. Encrypt your message if needed (PGP key to be published).

What we ask

Do not access data that is not yours, do not degrade the service, do not publicly disclose the vulnerability before it is fixed, and give us reasonable time to remediate.

What we commit to

Acknowledge receipt within a reasonable time, keep you informed of progress, fix as quickly as possible and credit you if you wish.

Scope

This policy covers assets operated by CYBERDUR. It does not authorise you to test our customers' systems.