Vulnerability Disclosure Policy (VDP)

This Privacy Policy was last updated on May 20, 2020. If there will be any update, amendment, or changes to our Privacy Policy then these will be posted on this page

Vulnerability Disclosure Policy (VDP) 

1) Purpose & Principles 

Cyber Heals and its product Truzta are committed to collaborative, responsible security research. This policy sets out how to report security vulnerabilities safely and constructively. We align our approach with ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111(vulnerability handling). 

Our principles: 

  • Safety first: protect users, data, and services.
  • Proportionality: keep testing low-impact and targeted.
  • Transparency: acknowledge, triage, remediate, and communicate.
  • Coordinated disclosure: fix issues promptly and disclose responsibly.
  • Good faith, no expectations: report vulnerabilities without conditions or expectations of payment.
2) Scope

In scope

Assets operated and controlled by Cyber Heals/Truzta, including:

  • Web apps, APIs, backend services, and agents under app.truzta.com, api.truzta.com, login.truzta.com
  • Publicly reachable services we operate in our cloud environments

Impactful classes typically include:

  • Authentication/authorization flaws (e.g., IDOR/BOLA, broken access control, account takeover)
  • Injection (SQL/command/template), RCE, SSRF with network impact
  • Sensitive data exposure with realistic harm
  • Business logic abuses with security impact
  • Misconfigurations that enable privilege escalation or data access
Out of scope (examples)
  • Volumetric or disruptive testing: DDoS, resource exhaustion, high-rate brute-force/fuzzing
  • Findings without demonstrable security impact: missing headers, non-sensitive banner/info leakage, clickjacking on non-sensitive pages
  • Weak TLS ciphers/legacy protocols without a viable exploit path
  • Social engineering or phishing of staff, customers, or partners
  • Physical security testing
  • Third-party platforms, vendors, or libraries we do not operate (report to the vendor)
  • Customer tenants and production billing/payment systems, unless we explicitly authorize testing
  • Non-production environments, unless we explicitly authorize testing

If you are unsure whether an asset is in scope, please email us before testing. Test account scan be provided on request.

3) Responsible Reporting (No Pay-to-Report)
We gratefully welcome reports without any expectation of compensation.

To keep the process professional and fair, we kindly ask that you do not:

  • Withhold, delay, or condition a report on a bounty, fee, or paid engagement
  • Use threats of disclosure or business harm to seek payment

We may, at our discretion, offer non-monetary recognition (e.g., Hall of Fame mention, thank-you note, or swag) for valid, impactful, policy-compliant reports.

4) How to Report
Email: security@cyberheals.com

Please include:

  • Asset & location: exact domain/URL, API path/method, app build/version
  • Issue & impact: concise description (e.g., “IDOR → cross-tenant read of invoices”)
  • Reproduction steps: step-by-step, benign PoC (minimal data; 2–3 records suffice)
  • Relevant requests/responses, headers, timestamps (with timezone), and testing IPs
  • Any safeguards you used to limit impact
  • Optional: screenshots/video and suggested remediation

Anonymous reports are welcome. Please avoid high-rate automated scans.

5) Our Commitments

  • Acknowledgment: within 72 business hours
  • Triage: confirm scope, validity, and severity (using CVSS v3.x and real-world impact)
  • Communication: status updates at meaningful milestones (triaged, accepted, fix in progress, resolved)

Target remediation timelines (targets, not guarantees):

  • Critical: aim ≤ 14 days
  • High: aim ≤ 30 days
  • Medium: aim ≤ 60 days
  • Low/Info: backlog or best-effort
  • Validation: we may invite you to confirm a fix in a controlled manner
  • Recognition: optional Hall of Fame entry after remediation for eligible reports

Eligibility for recognition: first valid reporter; non-duplicate; in-scope; respectful, low-impact testing; adherence to this policy. Pseudonyms are welcome.

6) Coordinated Disclosure

Our default embargo period is up to 90 days from acknowledgment, adjusted by severity and remediation complexity.
  • We may accelerate timelines for active exploitation or supply-chain risk.
  • If additional time is needed, we will request a reasonable extension.
  • Please refrain from publishing details or PoC code until we mutually agree the disclosure window and mitigations are in place.

7) Researcher Guidelines

To keep users and systems safe, please:

  • Use the minimum data required to demonstrate impact; stop if you encounter personal data, payment data, secrets, or production credentials, and report immediately.
  • Keep traffic low; avoid service degradation.
  • Do not modify or delete data, maintain persistence, pivot laterally, or plant backdoors.
  • Do not engage in social engineering/phishing or physical access attempts.
  • Do not scan third-party or clearly out-of-scope systems.

Data handling: securely delete any data obtained during testing within 30 days of resolution, or sooner if no longer needed for validation.

8) Legal & Safe-Harbor

This policy is intended to enable good-faith security research.

If you act in good faith, follow this policy, limit testing to in-scope assets, avoid privacy harm/service disruption, and promptly report findings, Cyber Heals will not pursue legal action for your research.

Please comply with applicable laws, including but not limited to:

United States

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. §1030
  • Digital Millennium Copyright Act (DMCA) §1201 (anti-circumvention)
  • Stored Communications Act (SCA), 18 U.S.C. §§2701–2712
United Kingdom
  • Computer Misuse Act 1990
  • Data Protection Act 2018 and UK GDPR

Other local computer misuse, privacy, and IP laws may apply based on your location. This policy does not waive any rights or create a bounty or contractual obligation.

Thank You

Your efforts directly strengthen the security of Cyber Heals and Truzta. We appreciate your professionalism and your partnership in protecting our customers.