Legal
Security Disclosure
Responsible disclosure guidelines for reporting security vulnerabilities in Cyber Mobility Shield websites and services.
1. Our commitment
Cyber Mobility Shield takes the security of our website, training portal, and connected tool workspaces seriously. We welcome good-faith reports from researchers, customers, and users.
This policy describes how to report vulnerabilities and what you can expect from us.
2. In scope
- cybermobilityshield.com and subdomains operated by us.
- The public training portal and authenticated learner profile flows on this domain.
- Marketing tool preview pages and links to CMS-operated workspaces explicitly hosted under our infrastructure or designated production URLs.
- API routes exposed by this website (for example, contact submission) when accessed in accordance with this policy.
3. Out of scope
- Third-party services (hosting providers, email delivery, YouTube, customer-managed deployments) except where a vulnerability clearly originates in our configuration.
- Social engineering, physical attacks, or spam/phishing against our staff.
- Denial-of-service attacks or automated scanning that degrades production availability.
- Issues requiring physical device access outside agreed test engagements.
- Findings in out-of-date browsers or unsupported client software without demonstrated impact on supported configurations.
4. How to report
Email contact@cybermobilityshield.com with the subject line “Security Disclosure”. Include:
- Description of the vulnerability and perceived impact.
- Steps to reproduce, proof-of-concept, and affected URLs or endpoints.
- Your contact details (optional but helps us coordinate fixes and acknowledgement).
- Whether you want public acknowledgement — we will ask before naming researchers.
5. Safe harbor
When you comply with this policy — act in good faith, avoid privacy violations, do not access or modify data beyond what is necessary to demonstrate the issue, and give us reasonable time to remediate — we will not pursue legal action related to your research.
This safe harbor does not apply if you violate law, exfiltrate personal data, or disrupt services.
6. Our response process
- Acknowledgement: target within 3 business days.
- Triage: assess severity and scope; we may ask clarifying questions.
- Remediation: prioritise fixes based on risk; we will keep you informed of material progress.
- Disclosure coordination: we prefer coordinated disclosure after a fix or mitigation is available.
7. Personal data during testing
Do not interact with real user accounts or personal data unless explicitly authorised under a written test agreement. Use test accounts or synthetic data. If you inadvertently access personal data, stop, report immediately, and delete local copies.
Reports involving personal data may also be subject to our Privacy Policy and DPDP Act obligations.
8. Recognition
We do not currently operate a public bug bounty programme or guaranteed monetary rewards. With your permission, we may acknowledge responsible disclosures in release notes or a security advisories page in the future.
