We believe in working with the security community to protect our users. If you've found a vulnerability in Cylvern's infrastructure, we want to hear from you.
Cylvern Security will not pursue legal action against researchers who discover and report vulnerabilities in good faith in accordance with this policy. We consider security research conducted under this VDP as authorised and will not refer researchers to law enforcement. We ask only that you do not disrupt services, exfiltrate data, or target users.
| Asset | Type | Notes |
|---|---|---|
cylsec.com |
Web | Main marketing site |
ctf.cylsec.com |
Web | CTF platform — all user-facing endpoints |
*.cylsec.com |
Subdomain | Any subdomain actively serving content |
| Severity | Examples | Acknowledgement | Resolution Target |
|---|---|---|---|
| Critical | RCE, auth bypass, mass data exfiltration | 24 hours | 7 days |
| High | SSRF, SQLi, privilege escalation | 48 hours | 14 days |
| Medium | Stored XSS, IDOR, sensitive info leak | 5 days | 30 days |
| Low / Info | Missing headers, clickjacking, open redirect | 7 days | 60 days |
Email security@cylsec.com with a clear title, steps to reproduce, proof-of-concept, and impact assessment.
We will acknowledge your report within the SLA window and assign a tracking reference.
Our team validates the vulnerability and assesses severity using CVSS 3.1.
We patch or mitigate the vulnerability and verify the fix in staging and production.
We coordinate disclosure timing with you. We aim for 90 days from initial report to public disclosure.
We recognise and thank the researchers who have responsibly disclosed vulnerabilities to us.
No submissions yet. Be the first to be listed here!
Send vulnerability reports to:
security@cylsec.comPlease include: vulnerability description, steps to reproduce, impact, affected asset, and any proof-of-concept.
For non-sensitive issues, you may also reach us on Discord:
discord.gg/gveJetDthVDo not post vulnerability details publicly in Discord — use private messages to a moderator.