Security Policy

How to report security issues to CyberXplainer Academy — and how we’ll handle them.

Responsible Disclosure

We appreciate the security community’s help in keeping our learners safe.

How to Report

Please email hello@cyberxplainer.com with:

  • Steps to reproduce the issue (affected URL, parameters, screenshots).
  • Impact assessment and any proof of concept.
  • Your preferred attribution (name/alias) if you want recognition.

Guidelines

  • Don’t access, modify, or exfiltrate data that isn’t yours.
  • Don’t run automated scans that could degrade site performance.
  • Give us reasonable time to investigate and fix before public disclosure.

Out of Scope (Examples)

  • Self‑XSS, clickjacking on static pages without sensitive actions.
  • Missing security.txt, lack of SPF/DMARC alignment, best‑practice recommendations.
  • Third‑party platform issues (e.g., vendor bugs outside our control).

Acknowledgments

We recognize researchers who responsibly disclose valid issues on our Hall of Fame (unless anonymity is requested).

Scope

This policy applies to cyberxplainer.com and subdomains operated by CyberXplainer.