Vulnerability Disclosure Policy
CB Solve welcomes responsible reports of suspected security vulnerabilities affecting systems and services that we operate.
Email christian@cbsolve.com with a concise description, the affected URL or service, reproduction steps and the potential impact. Do not include secrets or unrelated personal data.
Scope and responsible testing
Limit testing to systems clearly operated by CB Solve and to the minimum activity needed to demonstrate the issue. Do not:
- access, modify, retain or disclose data that is not yours;
- use denial-of-service, traffic flooding, destructive testing, malware or social engineering;
- attempt to gain persistence or move laterally after demonstrating a vulnerability;
- test third-party systems merely because CB Solve links to or integrates with them.
If you encounter data
Stop testing, do not copy or retain the data, and report the issue. Include only the minimum evidence required for us to reproduce and investigate it.
What to expect
We will acknowledge credible reports as soon as practicable, investigate them proportionately, and may ask for additional technical detail. Please allow us a reasonable opportunity to remediate a confirmed issue before public disclosure.
Rewards
This policy does not create a bug-bounty programme or promise payment, reward or other compensation.
Good-faith research
We will not intentionally pursue legal action against a researcher solely for good-faith activity that follows this policy. This statement does not authorise unlawful activity, access to third-party systems, privacy violations, extortion, disruption or activity outside the scope above.
Canonical security contact
Our machine-readable security contact is published at /.well-known/security.txt.