Skip to content
CyberVanta
Last updated 8 September 2026

Responsible disclosure

If you have found a security issue in a CyberVanta system, we want to hear about it and we will treat you fairly.

Scope

This policy covers cybervanta.tech and its subdomains, and any other system we publicly identify as ours. It does not cover our clients' systems: findings there should go to the client directly.

How to report

  • Email security@cybervanta.tech with a description of the issue, the steps to reproduce it, and any evidence.
  • Ask us for a PGP key if you need to encrypt sensitive details. Our contact details are also published at /.well-known/security.txt.
  • Give us a way to contact you. Anonymous reports are welcome but we cannot update you on them.

What we ask

  • Do not access, modify, or delete data that is not yours. If you reach data by accident, stop and tell us.
  • Do not run denial of service, social engineering, or physical attacks against us.
  • Give us reasonable time to fix the issue before publishing details. We aim for 90 days and will agree a date with you.

What you can expect

  • An acknowledgement within two business days.
  • An assessment and expected fix timeline within ten business days.
  • Credit on this page if you want it, once the issue is fixed.
  • No legal action for good-faith research that follows this policy. We consider it authorized under the Computer Misuse Act 1990 to the extent we are able to authorize it.