Bug bounty programme
Cyril runs a coordinated vulnerability disclosure programme. We welcome reports from security researchers acting in good faith and commit to never pursuing legal action against anyone who follows this policy.
How to report
Email security@getcyril.com.
Please include:
- A clear description of the vulnerability and its potential impact
- Step-by-step reproduction instructions, ideally with a minimal proof-of-concept
- The affected URL(s), endpoint(s), and any account context required
- Your CVSS estimate and severity tier (we will adjust if needed)
- Whether you would like public credit, and the name to use
We will acknowledge receipt within 2 business days. If you have not heard back within that window, please re-send — your message may have been filtered.
Severity & response times
| Severity | CVSS v3.1 | Examples | Target first response |
|---|---|---|---|
| Critical | 9.0–10.0 | Remote code execution; full database compromise; cross-tenant data exposure; payment-flow bypass | 24 hours |
| High | 7.0–8.9 | Authenticated privilege escalation; SSRF reaching internal services; auth bypass on a single endpoint | 48 hours |
| Medium | 4.0–6.9 | Stored XSS in an authenticated surface; CSRF on a state-changing endpoint; IDOR with limited blast radius | 5 business days |
| Low | 0.1–3.9 | Reflected XSS requiring victim interaction; rate-limit gaps without abuse path; informational leaks | 10 business days |
These are times to first triage, not times to fix. We will share a fix timeline as soon as the issue is reproduced and scoped. They are targets: the commitment we will hold ourselves to is the acknowledgement above — within 2 business days, whatever the severity. Cyril is a small team without a 24-hour on-call rota, and we would rather tell you that than publish a number we cannot always meet.
In scope
| Host | Surface |
|---|---|
app.getcyril.com | Staff app frontend |
api.getcyril.com | Public REST API + MCP audit endpoints |
admin.getcyril.com | Platform-admin frontend |
portal.getcyril.com | Client portal frontend (any subdomain or org-mapped CNAME) |
getcyril.com | This site, including its lead-capture and reporting endpoints |
*.getcyril.com | Customer-configured org subdomains pointed at Cyril. Excludes any host with a -staging suffix — see below. |
Out of scope
- Findings against staging or development environments (
*-staging.getcyril.com) - Third-party services we depend on — report directly to that vendor
- Social engineering of staff, customers, or vendors
- Physical attacks on facilities, hardware, or personnel
- Denial-of-service or volumetric attacks
- Spam, phishing, or anything that makes contact with non-consenting third parties
- Findings only reproducible with brute-forced credentials or stolen tokens
- Vulnerabilities affecting users of out-of-date browsers (we support the last two major versions of Chrome, Firefox, Safari, Edge)
- Self-XSS, missing security headers without a demonstrated impact, missing rate limits without an abuse path
- Reports based on automated scanner output without a working proof-of-concept
Safe harbour
Provided you act in good faith and follow this policy, Cyril considers your research to be authorised conduct. We will not pursue legal action — including under the Computer Misuse Act 1990 (UK), the Computer Fraud and Abuse Act (US), or analogous legislation in other jurisdictions — against you, and we will work with our sub-processors and law enforcement where necessary to support that protection.
You commit, in return, to:
- Stop testing as soon as you confirm the vulnerability — do not exfiltrate data beyond the minimum needed to demonstrate impact.
- Not access, modify, or destroy data belonging to other users or organisations.
- Not interrupt service for other users.
- Not publicly disclose the vulnerability before we have had a reasonable opportunity to fix it (typically 90 days, with extensions agreed in writing for complex remediations).
- Comply with all applicable laws.
Recognition
Cyril's programme is currently recognition-only. With your consent we credit reporters publicly on this page once a fix has shipped and a reasonable disclosure window has elapsed.
We are evaluating monetary bounties as the platform matures. When that ships, the rewards table will appear here with explicit minimums by severity and qualifying-vulnerability rules — and reporters who landed an eligible report before the change will be made whole retroactively.
Hall of fame
No public reports yet. Be the first.