🛡️ Responsible Disclosure Program

Report it. We'll fix it and credit you.

CyberDudeBivash runs a public Responsible Disclosure Program for the AI Security Hub platform. This page is the honest starting point: how to report, what we commit to, and how we recognize the researchers who help us — including exactly what we do not yet offer.

24h
Report Acknowledgment
24h
Critical Fix Target
72h
High Fix Target
7d
Medium Fix Target

Our security philosophy

We are a small, bootstrapped, pre-revenue cybersecurity company. We take that seriously precisely because we ask enterprises to trust us with security work — so our own disclosure program has to be honest about what we can and can't do today, not a copy-paste of a Fortune 500 program we can't back up.

🔍

We want your reports

Independent security research makes this platform safer. We would rather hear about an issue from a researcher, in good faith, than find it ourselves after it's exploited.

🤝

We won't come after you

Good-faith testing within the scope and rules of our Vulnerability Disclosure Policy is authorized. Read our full Safe Harbor commitment there.

💯

We won't overclaim

No fabricated bounty amounts, no "guaranteed" payouts, no inflated response times. What's published here is what we can actually deliver — see our Trust Center for the same standard applied platform-wide.

In-scope assets & out-of-scope testing

Testing is only authorized against the assets and methods listed below. Full detail, including rules of engagement, is in the Vulnerability Disclosure Policy.

✅ In scope

  • https://cyberdudebivash.in and subdomains
  • https://intel.cyberdudebivash.com and subdomains
  • https://tools.cyberdudebivash.com
  • Public APIs under /api/* on the above hosts

🚫 Out of scope

  • Denial-of-service or load/stress testing
  • Social engineering of staff, customers, or contractors
  • Physical security attacks on offices or hardware
  • Third-party services we depend on (Cloudflare, Razorpay, etc.)
  • Automated scanner output with no proof-of-concept

Report requirements

A well-formed report gets triaged faster. We prefer plain text or Markdown, in English, sent by email.

What to include

  • Clear summary and the affected URL/asset
  • Vulnerability type/category
  • Step-by-step reproduction instructions
  • Proof of concept (request/response, screenshot, or short video)
  • Your assessment of impact
  • Whether you'd like public credit, and how to attribute you

Preferred format

  • Plain text or Markdown email to [email protected]
  • One vulnerability per report
  • Attachments as PDF, PNG, or TXT — no executables
  • PGP-encrypt anything sensitive (see below)

Security contact

📧

Email

[email protected]

Monitored by the security team. This is the only channel we ask researchers to use for vulnerability reports.

🔐

PGP encryption

Placeholder — no key published yet. If your report contains sensitive details, email [email protected] first and ask for our current PGP key before sending them. We will not fabricate a key here just to have one on the page.

⏱️

Response SLA

Acknowledgment: 24 hours
Fix target — Critical: 24h · High: 72h · Medium: 7 days · Low: 30 days

Safe Harbor

Our commitment to good-faith researchers

CyberDudeBivash will not pursue legal action against, or refer to law enforcement, any researcher who discovers and reports a vulnerability in good faith, in accordance with this program's scope and rules. We consider such testing to be authorized. Full legal detail is published in the Vulnerability Disclosure Policy.

Disclosure timeline

1

You report

Email [email protected] with the details above.

2

We acknowledge

Within 24 hours, confirming receipt and opening a tracking reference.

3

We triage

We reproduce the issue and assign a severity using CVSS 3.1.

4

We fix

Remediation is shipped against the severity-based targets above.

5

We recognize you

Hall of Fame listing and a Certificate of Appreciation, credited the way you asked.

6

Coordinated disclosure

Public write-ups, by either party, wait until a fix is deployed and both sides agree.

Recognition program

What a valid, in-scope, good-faith report earns you today — and what it doesn't.

🏆

Hall of Fame listing

Public credit on our Security Researcher Hall of Fame, with your name, the finding category, and severity.

📜

Certificate of Appreciation

A verifiable, numbered certificate — see how verification works.

💼

LinkedIn recommendation

On request, a genuine LinkedIn recommendation from our security team describing your finding.

What we don't offer today: CyberDudeBivash does not currently operate a paid bug bounty program and does not promise monetary rewards of any kind. We are honest about this rather than implying otherwise. See our recognition policy and the Hall of Fame for who's already been recognized — starting with our first researcher, Ganesh RK.

Frequently asked questions

Does CyberDudeBivash pay bug bounties?

Not today. We're bootstrapped and pre-revenue. Valid reports get Hall of Fame recognition and a Certificate of Appreciation, not a monetary reward. See our honest future roadmap for what might change as the business grows.

Is my report confidential?

Yes, until a fix ships and we agree on disclosure together. See the Privacy section of the Vulnerability Disclosure Policy for what we do with your contact details.

Can I stay anonymous?

Yes. Tell us in your report if you'd prefer not to be named publicly — we'll still fix the issue, we just won't credit you by name.

What if I accidentally access data I shouldn't have?

Stop testing, do not view or exfiltrate more than the minimum needed to prove the issue, and tell us immediately in your report. This is covered under Safe Harbor as long as you act in good faith.

Found something? Tell us.

One email starts the process — no account, no form, no friction.