Legal / Responsible Disclosure

Responsible Disclosure

Version 26.08a

We appreciate the work of security researchers. If you believe you have found a security vulnerability in CyberIllumination™, we want to hear from you, and we will work with you to understand and resolve the issue quickly.

How to report

Email security@cyberillumination.us with: a description of the vulnerability and its potential impact; steps to reproduce it; and any relevant URLs, request/response captures, or screenshots. We will acknowledge your report within two (2) business days.

Our commitments

  • We will investigate every legitimate report and keep you informed as we work to resolve it.
  • We will not pursue legal action against researchers who comply with this policy in good faith.
  • With your permission, we will credit you once the issue is resolved.

Ground rules

  • Do not access, modify, or delete data that does not belong to you. If you encounter another organization’s data, stop and report immediately.
  • Do not degrade the service (no denial-of-service testing, no spam, no social engineering of our staff or clients).
  • Do not publicly disclose the vulnerability before we have resolved it and agreed on disclosure.
  • Only test against accounts you own or are authorized to use.

Out of scope

  • Findings from automated scanners without a demonstrated, exploitable impact.
  • Issues in third-party services we do not operate.
  • Missing best-practice headers or configurations without a demonstrated security impact.

Version

Change Log:
26.08a – 04-AUG-2026 – Initial CyberIllumination™ publication.