← CloudTune home

Security

Vulnerability disclosure policy

CloudTune accepts good-faith reports of security vulnerabilities affecting its public product surface, customer-isolated governed workflows, and related public web properties.

How to report

Email [email protected]. Include reproduction steps, affected URLs or API paths, impact, and the logs or screenshots needed to reproduce the issue. If encryption is required, request an encrypted handoff path in your first message.

Scope

Out of scope

Researcher expectations

CloudTune commitments

CloudTune will acknowledge credible reports, triage them, determine severity, and route them through its security incident process when needed. This policy does not authorize destructive testing.

Compensation

CloudTune does not currently run a public bug bounty. Reporting a vulnerability does not imply payment, an automatic reward, or managed researcher status.

Machine-readable security.txt · Plain-text policy