Our Commitment
- ✓ Acknowledgement of report receipt within 45 minutes during business hours (WIB), and within 1 business day outside business hours.
- ✓ Verification of the finding, severity assignment, and notification when a fix is released.
- ✓ Public recognition where desired — anonymity is permitted.
- ✓ Safe harbor for testing conducted in accordance with this policy.
No compensation. We do not operate a paid bug bounty program. There is no payment or physical reward for vulnerability reports.
Scope
| Asset | Description |
| cyberagent.id | Public site and policy pages served from this domain |
| www.cyberagent.id | Alias of the primary domain |
| docs.cyberagent.id | Public documentation and legal pages |
Not yet in scope: the dashboard and public API are marked coming soon and do not yet receive production traffic.
Out of Scope
- ✕ Infrastructure, hosting, DNS, and email providers
- ✕ Third-party services
- ✕ Denial of service, stress testing, high-volume brute force
- ✕ Social engineering and phishing
- ✕ Physical attacks and hardware testing
- ✕ Self-XSS and issues that require a victim to execute a script themselves
- ✕ Missing headers with no measurable impact
- ✕ Rate limiting and spam (by design)
- ✕ Other users' data — reported without downloading or storing it
- ✕ Uncoordinated bulk automated scanning
Testing Rules
- ✓ Non-destructive: do not modify, delete, or corrupt data or configuration.
- ✓ Use your own test data as proof of impact.
- ✓ If you encounter sensitive data, stop and report it — do not continue exploring.
- ✓ One report per issue, with clear reproduction steps.
- ✓ Do not publish findings before a fix is released and agreed upon.
How to Report
- Title and affected asset (exact URL/endpoint)
- Estimated severity and CVSS score where available
- Reproduction steps that can be replayed from a clean state
- Evidence: full request/response, timestamps, screenshots
- Demonstrable real-world impact — not theoretical potential
- Remediation recommendations, if any
founder@cyberagent.id
PGP encryption available on request.
Handling Process
| Stage | What happens |
| Confirmation | Report is logged and acknowledged (45 minutes during business hours) |
| Triage | Reproduction validation, severity assignment, remediation decision |
| Remediation | Critical targeted within 7 days, High within 14 days, the rest follow the release cycle |
| Verification | Notification once the fix is released |
| Publication | Coordinated disclosure (90 days by default) and recording of recognition |
Recognition
The reporter's name or handle is listed after the fix is released, unless you choose to remain anonymous. We still reply to informational findings by email — without listing them in the recognition list.