CyberCLI

Responsible disclosure

Found something? Tell us.

We build a security product. We owe you a fast, serious, human response when you tell us we broke something. The contact, scope, and what to expect are on this page. We follow RFC 9116; the machine-readable index is at /.well-known/security.txt.

Contact
security@cybercli.com

Email is the canonical channel. We monitor weekdays + on-call after hours. Acknowledgement reply within 1 business day. If you don't hear back in 2 business days, escalate to hello@cybercli.com — chris reads that personally.

What you can expect from us

Acknowledged within 1 business day

Reply from a human, not an autoresponder.

First triage within 5 business days

We confirm reproduction, classify severity, and tell you what we're doing.

Credit on the disclosure page

If you want credit (researcher name + handle), we'll list you on the published advisory. Anonymous is fine too.

No legal action for good-faith research

Safe-harbor commitment for testing within the scope below, in line with industry-standard responsible-disclosure norms.

Scope

In scope
  • · The CyberCLI product (single-binary engine, dashboard, CLI)
  • · Marketing site at cybercli.com (Astro + Cloudflare Pages)
  • · Licensing backend (Cloudflare Pages Functions + D1, including Stripe webhook + Passkey auth + License JWS signing)
  • · Released installer + signed artifacts (install.sh, GitHub Release tarballs + SHA256SUMS)
Out of scope
  • · Customer deployments of CyberCLI on their own infrastructure — they own that surface; we'll triage on request but it isn't ours to fix unilaterally
  • · Social-engineering attacks against CyberCLI staff or customers
  • · Denial-of-service via traffic flood against cybercli.com
  • · Third-party services we rely on (Cloudflare, Stripe, Resend, GitHub) — report those upstream; we'll coordinate if a CyberCLI-side change is needed

What to include in your report

  1. What you found, in one sentence at the top.
  2. Reproduction steps. The shortest path to the bug. Code, payloads, screenshots, request traces — whatever's clearest.
  3. Affected surface. cybercli CLI version, marketing-site URL, or backend endpoint.
  4. Severity per your read. We'll independently classify, but your impact assessment helps prioritization.
  5. How you'd like to be credited on the public advisory (or "anonymous").

Bounty

We do not yet run a paid bounty program. We're a young company; the budget for one comes after the first year of revenue. Until then, what we offer is the four commitments above — fast acknowledgement, real triage, public credit, safe harbor — plus genuine gratitude. The day we open a paid program, this section will say so explicitly, including the payout table.

RFC 9116 machine-readable index: /.well-known/security.txt

General contact: hello@cybercli.com · Architecture proof: /architecture · Trust ladder: /trust