Vulnerability disclosure policy
Aligned with ISO/IEC 29147 · Last updated: 2026-08-10
Scope #
This policy covers vulnerabilities in infrastructure I operate: cyberphoenix.gr and any *.cyberphoenix.gr subdomain under my control. It does not cover systems belonging to my employer or to any third party, and it does not grant permission to test them.
How to report #
Email info@cyberphoenix.gr with:
- A clear description of the vulnerability and the affected component
- Reproduction steps and, where possible, a minimal proof-of-concept
- Your assessment of the impact
- Whether you want to be credited, and how
What you can expect #
- Acknowledgement within 3 business days of receipt
- Triage and validation within 10 business days
- Coordinated disclosure window of 90 days from acknowledgement, extendable by mutual agreement where remediation is non-trivial
- Status updates at meaningful milestones
Safe harbor #
If you make a good-faith effort to follow this policy during your research, I will consider that research authorized, will not pursue or support legal action over it, and will work with you to resolve the issue. With your consent I'm glad to credit you.
"Good faith" excludes: destroying or modifying data, denial-of-service testing without prior written consent, social engineering, accessing or copying data beyond the minimum needed to demonstrate the issue, and anything that breaks applicable law.
Out of scope #
- Automated scanner output with no working proof-of-concept
- Missing best-practice headers where there is no demonstrated security impact
- Issues requiring physical access or an already-compromised endpoint
- Spam, phishing, or social-engineering reports
Machine-readable contact #
See /.well-known/security.txt (RFC 9116).