Legal & Governance

Vulnerability Disclosure Policy

Cyber Resilience values responsible security research and encourages the responsible disclosure of legitimate security vulnerabilities affecting our systems, platforms, applications, or services.

This policy is intended to support coordinated vulnerability disclosure while protecting operational integrity, clients, users, systems, and researchers.

On This PAge

REPORTING A VULNERABILITY

Suspected vulnerabilities should be reported responsibly and in good faith to:

info@cyberres.co.za

Reports should include sufficient detail to allow validation and investigation, including:

  • affected system or page;
  • technical description of the issue;
  • steps required to reproduce the issue;
  • potential impact;
  • screenshots or supporting evidence where appropriate.

RESPONSIBLE DISCLOSURE EXPECTATIONS

Researchers are expected to:

  • avoid disruption to services or operations;
  • avoid unauthorised access to data;
  • avoid modification or destruction of information;
  • avoid social engineering, denial-of-service activity, or operational interference;
  • and provide Cyber Resilience a reasonable opportunity to investigate and remediate vulnerabilities before public disclosure.

OUR COMMITMENT

Cyber Resilience will make reasonable efforts to:

  • acknowledge legitimate submissions;
  • investigate reported vulnerabilities;
  • maintain communication where appropriate;
  • and remediate validated issues according to operational risk and severity.

Submission of a vulnerability report does not create entitlement to compensation, payment, or a contractual relationship unless explicitly agreed.