Disclosure policy
Tell us, and we will not come after you.
How to report
Email security@cidra.dev with enough detail to reproduce the issue. A proof of concept helps; a working exploit is not required and never expected.
What we commit to
- Acknowledgement within one business day.
- An initial assessment, with our severity view and reasoning, within five business days.
- Progress updates at least every ten business days until resolution.
- Credit in the advisory, unless you would rather remain anonymous.
- No legal action, and no request that your host take action against you, for research conducted under this policy.
Safe harbour
Research conducted in good faith under this policy is authorised. We will not pursue or support action against you for it. Good faith means: you tested only accounts and data you own or were given permission to use, you stopped as soon as you had confirmed the issue, you did not degrade the service for anyone else, and you did not access, modify or retain another organisation’s data.
If you are unsure whether something is in scope, ask first. We would much rather answer a question than receive a report we cannot protect you for.
Out of scope
Denial of service, social engineering of our staff or customers, physical attacks, and findings from automated scanners submitted without validation. Reports about customer estates belong to those customers, not to us — please report them to the organisation concerned.
Disclosure timing
We aim to ship a fix within 90 days and will coordinate publication with you. If a fix will take longer, we will say so and explain why rather than let the clock run quietly. You are free to publish after 90 days regardless of our progress.