SECURITY
Responsible Disclosure
A safe path for reporting potential vulnerabilities without crossing CyberDefender's private trust boundaries.
Good-faith security research
CyberDefender welcomes responsible reports about vulnerabilities affecting the public website or explicitly authorized pilot surfaces. Do not access unrelated systems, customer data or private Owner/Admin functions.
Before reporting
- Do not include passwords, fleet tokens, private keys or other credentials in the initial report.
- Do not perform destructive testing, denial of service, persistence, data destruction or social engineering.
- Do not test third-party systems that are outside CyberDefender's authorization.
- Stop if you encounter private or customer data you were not authorized to access.
How to contact us
For an initial non-sensitive report, email ozodabdugafurov72@gmail.com with the subject SECURITY DISCLOSURE. Do not send credentials, private keys, exploit payloads or sensitive customer data in the first message. Agree on a secure channel before sharing sensitive evidence.
What to include
Provide the affected public URL or component, a concise description, reproducible non-destructive steps, expected versus observed behavior and the potential security impact.