cyberagent.id · docs Responsible Disclosure

Vulnerability Disclosure Policy

We accept security vulnerability reports from independent researchers. Every report is verified and acted upon by our engineers. This policy is recognition-only: there is no monetary reward, credit, or prize for accepted reports.

Our Commitment

No compensation. We do not operate a paid bug bounty program. There is no payment or physical reward for vulnerability reports.

Scope

AssetDescription
cyberagent.idPublic site and policy pages served from this domain
www.cyberagent.idAlias of the primary domain
docs.cyberagent.idPublic documentation and legal pages
Not yet in scope: the dashboard and public API are marked coming soon and do not yet receive production traffic.

Out of Scope

Testing Rules

How to Report

PGP encryption available on request.

Handling Process

StageWhat happens
ConfirmationReport is logged and acknowledged (45 minutes during business hours)
TriageReproduction validation, severity assignment, remediation decision
RemediationCritical targeted within 7 days, High within 14 days, the rest follow the release cycle
VerificationNotification once the fix is released
PublicationCoordinated disclosure (90 days by default) and recording of recognition

Recognition

The reporter's name or handle is listed after the fix is released, unless you choose to remain anonymous. We still reply to informational findings by email — without listing them in the recognition list.

© 2026 CyberAgent.id — Vulnerability Disclosure cyberagent.id · FAQ · Terms · Privacy