Responsible Disclosure
Version 26.08a
We appreciate the work of security researchers. If you believe you have found a security vulnerability in CyberIllumination™, we want to hear from you, and we will work with you to understand and resolve the issue quickly.
How to report
Email security@cyberillumination.us with: a description of the vulnerability and its potential impact; steps to reproduce it; and any relevant URLs, request/response captures, or screenshots. We will acknowledge your report within two (2) business days.
Our commitments
- We will investigate every legitimate report and keep you informed as we work to resolve it.
- We will not pursue legal action against researchers who comply with this policy in good faith.
- With your permission, we will credit you once the issue is resolved.
Ground rules
- Do not access, modify, or delete data that does not belong to you. If you encounter another organization’s data, stop and report immediately.
- Do not degrade the service (no denial-of-service testing, no spam, no social engineering of our staff or clients).
- Do not publicly disclose the vulnerability before we have resolved it and agreed on disclosure.
- Only test against accounts you own or are authorized to use.
Out of scope
- Findings from automated scanners without a demonstrated, exploitable impact.
- Issues in third-party services we do not operate.
- Missing best-practice headers or configurations without a demonstrated security impact.
Version
Change Log:
26.08a – 04-AUG-2026 – Initial CyberIllumination™ publication.