Report a Vulnerability

As a security education site, we hold ourselves to the standards we teach. If you've found a security issue on cyunified.com itself, we want to hear about it — and we commit to engaging with good-faith reports in good faith.

Scope

This policy covers cyunified.com and its subdomains only. It does not cover third-party sites we link to from our lessons (including any external practice labs) — please report issues on those sites directly to their own owners.

How to report

Email cyunified@gmail.com with as much of the following as you can:

  • A clear description of the vulnerability and its potential impact
  • The affected URL(s) or page(s)
  • Step-by-step instructions to reproduce it
  • Any proof-of-concept request, screenshot, or payload used (please avoid destructive testing)

What to expect

We're a small team, so we can't offer a guaranteed response SLA, but we'll acknowledge genuine reports as promptly as we can and keep you updated as we investigate and fix the issue.

Safe harbor

We won't pursue legal action against anyone who discovers and reports a vulnerability in good faith, provided you: avoid accessing, modifying, or exfiltrating data beyond what's needed to demonstrate the issue; avoid degrading the availability of the site for other users; give us reasonable time to investigate and remediate before disclosing the issue publicly; and don't use automated scanning tools that generate excessive load.

Please don't

Test for vulnerabilities against any third party using techniques found on this site — this policy only authorizes testing against cyunified.com itself. Attempting social engineering, physical security testing, or denial-of-service attacks against our infrastructure is out of scope and not covered by this policy.

Thank you for helping keep CyUnified secure — see also our Security Practices page for how we approach protecting this site.