Home / Legal
Legal
Responsible disclosure
We sell software that breaks into applications for a living. Punishing anyone for pointing the same attention at ours would be absurd. Here is how to tell us, and what we do next.
Last updated: 20 September 2026
How to report
Email hello@cyberlop.com with "Security" at the front of the subject line, and it is routed straight to the people who can fix it. If you would rather encrypt the report, ask in a one-line email and we will send you a key to use.
What to put in it
- Which part of Cyberlop is affected, and the URL or component
- Steps that reproduce it, in enough detail that we can follow them without guessing
- What an attacker gets out of it, because impact matters more than the class of bug
- Any proof of concept, screenshot or request and response you captured
- How you would like to be credited, or that you would rather not be
One issue per report, please. Two flaws in one email is how the second one gets forgotten.
What you can expect from us
- A human acknowledgement within two working days, not an auto-reply
- Our assessment and the severity we have assigned within five working days
- Updates as we work, rather than silence until it is closed
- Public credit when the fix ships, if you want it, and no mention of you at all if you do not
- A straight answer if we decide not to fix something, including why
Safe harbour
If you make a good-faith effort to follow this policy, we will treat your research as authorised. We will not pursue legal action against you, we will not ask anyone else to, and if a third party comes after you for work that stayed inside these rules, we will say publicly that it was authorised. Good faith means you stopped when you had proof, you did not take more data than a demonstration needed, and you told us before you told anyone else.
In scope
- The Cyberlop console and API at app.cyberlop.com
- The self-hosted agent and its container image
- docs.cyberlop.com
- This marketing site
Out of scope
- Denial of service, load testing, or anything that degrades the service for other customers
- Social engineering of our team, our customers or our suppliers, and any physical attack
- Another customer's tenant, account or data. Use your own, always
- Applications our customers test with Cyberlop. They are not ours; report those to the owner.
- Raw scanner output with no demonstrated impact, and missing best-practice headers that nothing can be exploited through
- Services we do not run, even where we link to them
Ground rules
- Test against your own account and your own tenant.
- If you reach personal data, stop at once, do not keep a copy, and tell us in the report.
- Give us a fair window to ship a fix before you publish. Tell us your intended date and we will tell you honestly whether we can meet it.
Is there a bounty?
No. There is no paid bug bounty today. We are a small company and we would rather say that plainly than advertise rewards we cannot reliably pay. What you get is a fast human reply, a real fix, the credit if you want it, and our genuine thanks. If that changes, this page changes with it.
A flaw in your own application?
This page is only about Cyberlop itself. If you have found something in an application that one of our customers tests with us, report it to that company. If you cannot reach anyone there and you believe the issue is serious, write to us and we will pass it on to the right people without repeating the technical detail to anyone else.
Anything else about this page
Questions about the process above, rather than a report itself, go to hello@cyberlop.com or the contact page. Actual reports belong in an email with "Security" at the front of the subject line, as described above.