Safe reporting and documented response

Responsible Vulnerability Disclosure Policy

This policy defines the reporting channel, scope, safe conduct, researcher expectations, and Cup Code’s response to a security report.

Published and effective as an operational document, without claiming external legal review

This is a public operational text. It does not replace a project contract, a product-specific privacy notice, or legal review based on the organization and its actual service providers.

Document code
POL-PUB-SECURITY-001
Version
1.0.0
Effective date
Content review
Next review
Owner
Governance and privacy
Authoritative version
Arabic. If translations differ, the Arabic text prevails, subject to applicable law and contract.
Contact channel
studio@cupcodestudio.com
Scope

Public website, accounts, and connected digital services

Audience

Visitors, users, and clients

Jurisdiction

Kingdom of Saudi Arabia, subject to other mandatory laws where applicable

Operational publication authority

Cup Code operational publication catalog

Document summary

This policy defines the reporting channel, scope, safe conduct, researcher expectations, and Cup Code’s response to a security report.

Reporting channel

Use the security reporting form. Send a description, reproduction steps, impact, product and version, and limited evidence. Do not send live secrets or more personal data than necessary.

Scope

Scope covers assets explicitly identified by Cup Code. Client or vendor services, social accounts, physical testing, and social engineering are out of scope without written owner authorization.

Safe research conduct

Test with minimum impact using your own accounts and test data, and stop when data access or modification capability is reached. Do not continue to prove greater impact, extract data, or disrupt service.

Prohibited activity

Denial of service, spam, persistence, disclosure extortion, publication of an exploitable issue before remediation, staff testing, and modification of data not owned by the researcher are prohibited.

Report quality

The report must support safe reproduction. State assumptions, limitations, and whether data was touched. Do not send executables. Use redacted text or video and remove tokens and data.

Cup Code response

We acknowledge receipt, triage severity, assign an owner, request needed information, and update the researcher at material stages. No reward is promised unless an approved program defines eligibility and amount.

Confidentiality and publication

We request reasonable time to verify, remediate, and update. Publication timing and scope are discussed with the researcher. We do not attribute details without consent or demand indefinite silence after risk is removed.

Good-faith research

When a researcher follows this policy, stops at risk, and reports promptly, we treat the activity as good-faith research and focus on remediation. This policy does not authorize violation of law, contract, or third-party rights.

Reports involving personal data

The report is isolated and privacy incident assessment begins. Access is restricted and notification decisions and deadlines are recorded. The researcher is not asked to retain a copy of data after receipt is confirmed.

Official references

References used to prepare this content

Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.

Versions

Change log

  1. Version 1.0.0

    Published the first operational version with clear scope, responsibilities, rights, and escalation routes.