Security and Responsible Disclosure
CYDENiC, Inc. values good-faith reports that may help protect the security of its public Website and related systems.
Reporting a Security Concern
To report a potential security vulnerability involving the public Website, email privacy@cydenic.com with the subject line: Security Report.
Please include, where available:
- The affected page, host, or service;
- A clear description of the issue and its potential impact;
- Steps needed to reproduce the issue;
- Relevant screenshots, logs, or proof-of-concept details that do not expose sensitive data;
- The date and time the issue was observed; and
- Your preferred contact information.
Good-Faith Expectations
Security research and testing must be lawful, proportionate, and designed to avoid harm. A report does not authorize access to customer environments, accounts, nonpublic systems, confidential information, personal information, or data belonging to another person.
Do not:
- Access, copy, modify, delete, corrupt, encrypt, or exfiltrate data;
- Disrupt Website availability or degrade service;
- Use denial-of-service, destructive, social-engineering, phishing, malware, or physical-security techniques;
- Attempt to obtain employee, contractor, customer, or third-party credentials;
- Create persistence, establish unauthorized accounts, or maintain access after testing;
- Publicly disclose a suspected issue before CYDENiC has had a reasonable opportunity to investigate and address it; or
- Demand payment, threaten disclosure, or condition non-disclosure on compensation.
CYDENiC's Response
CYDENiC may acknowledge a report, request additional information, investigate the matter, coordinate remediation, and communicate when the matter is resolved or otherwise closed. The timing and scope of any response will depend on severity, reproducibility, affected systems, and available information.
No Guarantee, Bounty, or Waiver
Submission of a report does not create a contract, confidential relationship, employment relationship, payment obligation, bug-bounty entitlement, or guarantee of a response.
Nothing on this page waives any legal right or remedy of CYDENiC or another party, and this page does not authorize activity that would otherwise be unlawful or prohibited.
Scope
This page applies to the public Website unless CYDENiC expressly identifies another system as in scope in writing. Customer systems, third-party services, production data, and nonpublic environments are outside scope unless expressly authorized.