Trust
Responsible Disclosure Policy
Cybersentinels Consulting, trading as Cybersentinels Consulting, values good-faith reports that help us identify and address security issues in approved Cybersentinels-owned public systems. This policy explains the limited testing we authorize, how to report a suspected vulnerability and the conduct required for coordinated disclosure.
This is not a bug-bounty program and does not promise payment, reward, recognition or employment.
2. In-Scope Systems
Only the following assets operated and controlled by Cybersentinels Consulting are in scope for security testing:
If an asset is not expressly listed, it is considered out of scope. Client systems, partner systems, employee accounts, third-party services, social media accounts, infrastructure not owned or controlled by Cybersentinels Consulting, and lookalike or unrelated domains are strictly out of scope.
- https://cybersentinal-testing.netlify.app/
- Public website and its directly associated web application functionality
- Public APIs hosted and operated by Cybersentinels Consulting, where specifically identified
2. In-Scope Systems
Only the following assets operated and controlled by Cybersentinels Consulting are in scope for security testing:
If an asset is not expressly listed, it is considered out of scope. Client systems, partner systems, employee accounts, third-party services, social media accounts, infrastructure not owned or controlled by Cybersentinels Consulting, and lookalike or unrelated domains are strictly out of scope.
- https://cybersentinal-testing.netlify.app/
- Public website and its directly associated web application functionality
- Public APIs hosted and operated by Cybersentinels Consulting, where specifically identified
4. Prohibited Testing
- Denial-of-service, resource exhaustion, stress or load testing
- Social engineering, phishing, impersonation or physical intrusion
- Malware, ransomware, destructive payloads, persistence or command-and-control
- Password spraying, credential stuffing, brute force or use of leaked credentials
- Testing involving employees, clients, partners or other users
- Accessing messages, files, databases, secrets or personal information
- Changing, deleting, corrupting, encrypting or exfiltrating data
- Automated scanning at a volume that could affect service or create excessive alerts
- Testing third-party services, dependencies or infrastructure without their separate authorization
- Extortion, threats, demands or conditioning non-disclosure on payment
- Public disclosure before remediation coordination
- Any activity prohibited by law or outside the listed scope
5. How to Report a Vulnerability
Please report suspected security vulnerabilities to info@cybersentinel.com. Do not use the general contact or careers form for security reports. If a report contains sensitive information, avoid including unnecessary confidential data and request a secure submission method before sharing it.
Include the following information where available:
Please do not include unnecessary personal information, client data, credentials, passwords, secrets, malware or large data extracts in your report. Only provide the minimum information necessary to demonstrate the vulnerability.
- Affected in-scope asset and exact location
- Description of the vulnerability and potential impact
- Clear steps to reproduce the issue
- Minimal proof of concept or sanitized request and response details
- Date, time and relevant test account
- Tools or source IP address, if useful for investigation
- Whether any data or other users may have been affected
- Your preferred contact details and disclosure expectations
6. What You Can Expect
We will make reasonable efforts to:
These response targets are not service-level commitments. Response and remediation timelines may vary depending on severity, reproducibility, technical complexity, dependencies and overall risk. We may not provide detailed information about internal remediation activities or third-party systems.
- Acknowledge a vulnerability report within 3 business days
- Review whether the report affects an in-scope Cybersentinels-owned asset
- Request additional information or clarification where needed
- Provide updates when practical during the review process
- Coordinate remediation and any agreed disclosure where appropriate
7. Safe-Harbor Intent
If you make a good-faith effort to comply with this policy, stay within the listed scope and avoid harm, we will not initiate legal action against you solely for that authorized research. If a third party initiates action and you complied with this policy, we may clarify that your activity was conducted under this policy where appropriate and legally permitted.
This statement does not bind third parties, regulators or law-enforcement authorities; excuse unlawful conduct; authorize activity on systems we do not own; waive rights relating to extortion, threats, data misuse or harm; or prevent action required to protect users, clients or systems. If you are uncertain whether an action is permitted, stop and ask us before proceeding.
8. Disclosure and Confidentiality
Do not publicly disclose a suspected or confirmed issue, related technical detail or affected information until we provide written approval or the parties agree on a coordinated disclosure date. We will consider reasonable disclosure requests but must protect users, clients, systems and legal obligations.
9. Rewards and Recognition
We do not currently operate a monetary bug-bounty program. Any recognition or reward is entirely discretionary, subject to eligibility, law, sanctions, tax, identity and other checks, and must be confirmed in writing. Do not conduct testing with an expectation of payment.
10. Privacy
We use reporter contact and report information to investigate, communicate, protect systems, maintain records, comply with law and establish or defend legal claims. See the Privacy Notice for additional information. Avoid submitting unnecessary personal information.
11. Policy Changes
We may update, suspend or withdraw this policy. Testing is governed by the version in effect when the activity occurs. Check this page before testing.
12. Contact
Security reports: info@cybersentinel.com
Policy and privacy questions: info@cybersentinel.com
- Replace all square-bracketed contact and legal placeholders.
- Confirm the founding year, headquarters wording and the 20+ client statement.
- Obtain written approval before displaying any client name, logo, testimonial or identifiable case study.
- Confirm that every listed service is currently deliverable directly or through an approved delivery model.
- Validate regulatory and standards-related wording before publication and whenever applicable requirements change.
- Do not describe SOC 2 as a certification or imply that Cybersentinels issues certifications, attestations or formal assessment outcomes.
- Do not use certification or accreditation logos without documented authorization.
- Connect every CTA to the relevant page, form or scheduling workflow.
- Test inquiry and newsletter consent flows against the final Privacy Notice.
- Review the final website copy after design implementation to ensure that headings, qualifiers and disclaimers have not been removed or separated from their context.
