The security of our software is a top priority. Cubbit welcomes feedback from security researchers, ethical hackers, users, and the general public to help make our systems more secure. If you believe you have discovered a vulnerability that could compromise the security of Cubbit DS3, please contact us. This Cubbit Vulnerability Disclosure Program (the ‘C-VDP’) explains the steps for reporting vulnerabilities, what we expect from you, and what you can expect from us.
When working with us, according to this C-VDP, you can expect us to:
Vulnerability reports must be related to the following:
Endpoints list:
We reserve the right to update this list from time to time without notice.
We encourage the reporting of vulnerabilities that include, but are not limited to:
Some types of reports are not covered by this C-VDP. Vulnerabilities not accepted include:
As a token of appreciation for those reporting security vulnerabilities that comply with the C-VDP, we offer a reward based on the severity and impact of the reported vulnerability. The evaluation will be at our discretion and in line with security best practices.
We offer up to 2.000,00€ per vulnerability depending on category and severity.
Out-of-scope vulnerability reports will not be eligible for recognition.
When conducting vulnerability research, according to this C-VDP, we consider this research conducted under this policy to be:
As always, you are expected to comply with all applicable laws. If a third party initiates legal action against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
If at any time you have concerns or are still determining whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.
Note that the Safe Harbor applies only to legal claims under the control of the organisation participating in this policy and that the policy does not bind independent third parties.
We reserve the right to modify or terminate this C-VDP at any time. Participation in this C-VDP does not create any contractual relationship with us. While we strive to evaluate each vulnerability in good faith, we are not obligated to provide rewards for reported vulnerabilities.
If you have any questions regarding this policy or want to report a vulnerability, you can contact us at security@cubbit.io.