Document summary
This policy defines the reporting channel, scope, safe conduct, researcher expectations, and Cup Code’s response to a security report.
Reporting channel
Use the security reporting form. Send a description, reproduction steps, impact, product and version, and limited evidence. Do not send live secrets or more personal data than necessary.
Scope
Scope covers assets explicitly identified by Cup Code. Client or vendor services, social accounts, physical testing, and social engineering are out of scope without written owner authorization.
Safe research conduct
Test with minimum impact using your own accounts and test data, and stop when data access or modification capability is reached. Do not continue to prove greater impact, extract data, or disrupt service.
Prohibited activity
Denial of service, spam, persistence, disclosure extortion, publication of an exploitable issue before remediation, staff testing, and modification of data not owned by the researcher are prohibited.
Report quality
The report must support safe reproduction. State assumptions, limitations, and whether data was touched. Do not send executables. Use redacted text or video and remove tokens and data.
Cup Code response
We acknowledge receipt, triage severity, assign an owner, request needed information, and update the researcher at material stages. No reward is promised unless an approved program defines eligibility and amount.
Confidentiality and publication
We request reasonable time to verify, remediate, and update. Publication timing and scope are discussed with the researcher. We do not attribute details without consent or demand indefinite silence after risk is removed.
Good-faith research
When a researcher follows this policy, stops at risk, and reports promptly, we treat the activity as good-faith research and focus on remediation. This policy does not authorize violation of law, contract, or third-party rights.
Reports involving personal data
The report is isolated and privacy incident assessment begins. Access is restricted and notification decisions and deadlines are recorded. The researcher is not asked to retain a copy of data after receipt is confirmed.
Official references
References used to prepare this content
Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.
Versions
Change log
- Version 1.0.0
Published the first operational version with clear scope, responsibilities, rights, and escalation routes.