Responsible disclosure

Last updated August 2026

This document describes the platform’s real data practices and is pending review by legal counsel.

We take the security of our own platform seriously and welcome reports from the security community. If you believe you have found a vulnerability in CyberHacker.ai, we want to hear from you and will work with you to resolve it.

How to report

Email [email protected]with the subject line “Security vulnerability report” and enough detail to reproduce the issue: the affected URL or component, the steps, and the impact. If you can, include a proof of concept.

Our commitment to you

  • We will acknowledge your report within 3 business days.
  • We will keep you updated as we investigate and remediate.
  • We will not pursue or support legal action against researchers who act in good faith under this policy.
  • With your permission, we are glad to credit you once the issue is fixed.

Guidelines — please do

  • Report as soon as you discover a potential issue.
  • Give us reasonable time to fix an issue before disclosing it publicly.
  • Only interact with accounts you own or have explicit permission to access.

Please do not

  • Access, modify or delete other users’ data.
  • Run automated scanning that degrades or disrupts the service, or denial-of-service tests.
  • Use social engineering, phishing, or physical attacks against our staff or facilities.
  • Publicly disclose a vulnerability before we have resolved it.

Scope

This policy covers the CyberHacker.ai platform and marketing site at our own domains. It does notauthorise testing of our customers’ assets, our sub-processors, or any third-party service. Testing a customer’s targets is only ever done through a commissioned engagement with that customer’s authorisation.