Security
Vulnerability disclosure policy
CloudTune accepts good-faith reports of security vulnerabilities affecting its public product surface, customer-isolated governed workflows, and related public web properties.
How to report
Email [email protected]. Include reproduction steps, affected URLs or API paths, impact, and the logs or screenshots needed to reproduce the issue. If encryption is required, request an encrypted handoff path in your first message.
Scope
cloudtune.orgpublic web properties- CloudTune application APIs and governed workflow surfaces
- Authentication, authorization, evidence integrity, and export boundaries reachable in supported deployments
Out of scope
- Social engineering, phishing, or physical attacks
- Denial-of-service testing, automated volumetric scanning, or destructive load testing
- Reports requiring access to another customer's data without evidence of a boundary failure
- Third-party service issues without a CloudTune-specific integration flaw
Researcher expectations
- Do not exfiltrate, modify, or destroy customer data.
- Stop once you have enough evidence to demonstrate the issue.
- Do not run persistence, lateral movement, or privilege-escalation steps beyond what is necessary to prove the bug.
- Give CloudTune a reasonable remediation window before public disclosure.
CloudTune commitments
CloudTune will acknowledge credible reports, triage them, determine severity, and route them through its security incident process when needed. This policy does not authorize destructive testing.
Compensation
CloudTune does not currently run a public bug bounty. Reporting a vulnerability does not imply payment, an automatic reward, or managed researcher status.