Vulnerability disclosure policy
If you have found a security issue affecting GTA Cyber, we would like to hear about it.
How to report
Email security@gta-cyber.org with enough detail for us to reproduce the issue: the affected host or URL, the steps you took, and what you observed. Screenshots or a short recording help.
Please report in English.
What this policy covers
This policy applies to gta-cyber.org and gta-cyber.com, which we operate. It does not cover Global Tech Advocates itself, its other networks, or our sponsors and partners, each of whom run their own disclosure processes. Issues affecting Klarvant should go to Klarvant directly.
What we ask
- Give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly or to any third party.
- Do not access, modify or delete data that does not belong to you.
- Do not degrade our services. No denial of service, no automated scanning that generates significant load, no social engineering of our people or our members.
- Stay within the law.
If you follow the above in good faith, we will not pursue or support legal action against you in relation to your research.
What you can expect
- An acknowledgement that a human has read your report, normally within five working days.
- An honest assessment of whether we consider it an issue, and why.
- Credit for the finding if you would like it, and if the report is valid.
Payment
GTA Cyber does not operate a bug bounty programme and does not offer payment for vulnerability reports. We are a volunteer-led not-for-profit with no budget for one. We are grateful for reports regardless, and we will say so, but please do not submit one expecting a fee or an invoice to be honoured.
Out of scope
The following are unlikely to receive a substantive response, because this is a static website with no accounts, no user data and no application logic:
- Missing security headers with no demonstrated exploit.
- Findings produced solely by an automated scanner, with no accompanying analysis.
- Reports about email configuration where the record in question is deliberate.
- Theoretical issues with no realistic path to impact.
- Anything relating to software or services we do not operate.
A note on the obvious
We are a cybersecurity guild. We are aware that this makes our own security posture fair game, and we would rather hear from you than not. Reports about this site are read by practitioners, not by a ticketing system.