Reply from a human, not an autoresponder.
Responsible disclosure
Found something? Tell us.
We build a security product. We owe you a fast, serious, human response when you tell us we broke something. The contact, scope, and what to expect are on this page. We follow RFC 9116; the machine-readable index is at /.well-known/security.txt.
Email is the canonical channel. We monitor weekdays + on-call after hours. Acknowledgement reply within 1 business day. If you don't hear back in 2 business days, escalate to hello@cybercli.com — chris reads that personally.
What you can expect from us
We confirm reproduction, classify severity, and tell you what we're doing.
If you want credit (researcher name + handle), we'll list you on the published advisory. Anonymous is fine too.
Safe-harbor commitment for testing within the scope below, in line with industry-standard responsible-disclosure norms.
Scope
- · The CyberCLI product (single-binary engine, dashboard, CLI)
- · Marketing site at cybercli.com (Astro + Cloudflare Pages)
- · Licensing backend (Cloudflare Pages Functions + D1, including Stripe webhook + Passkey auth + License JWS signing)
- · Released installer + signed artifacts (install.sh, GitHub Release tarballs + SHA256SUMS)
- · Customer deployments of CyberCLI on their own infrastructure — they own that surface; we'll triage on request but it isn't ours to fix unilaterally
- · Social-engineering attacks against CyberCLI staff or customers
- · Denial-of-service via traffic flood against cybercli.com
- · Third-party services we rely on (Cloudflare, Stripe, Resend, GitHub) — report those upstream; we'll coordinate if a CyberCLI-side change is needed
What to include in your report
- What you found, in one sentence at the top.
- Reproduction steps. The shortest path to the bug. Code, payloads, screenshots, request traces — whatever's clearest.
- Affected surface.
cybercliCLI version, marketing-site URL, or backend endpoint. - Severity per your read. We'll independently classify, but your impact assessment helps prioritization.
- How you'd like to be credited on the public advisory (or "anonymous").
Bounty
We do not yet run a paid bounty program. We're a young company; the budget for one comes after the first year of revenue. Until then, what we offer is the four commitments above — fast acknowledgement, real triage, public credit, safe harbor — plus genuine gratitude. The day we open a paid program, this section will say so explicitly, including the payout table.
RFC 9116 machine-readable index: /.well-known/security.txt
General contact: hello@cybercli.com · Architecture proof: /architecture · Trust ladder: /trust