# CloudTune Vulnerability Disclosure Policy CloudTune accepts good-faith reports of security vulnerabilities that affect the public CloudTune product surface, customer-isolated governed workflows, and related public web properties. ## How to report - Email `yanzewu88@gmail.com`. - Include reproduction steps, affected URLs or API paths, impact, and any logs or screenshots needed to reproduce the issue. - If encryption is required for a report, request an encrypted handoff path in the first message. ## Scope - `cloudtune.org` public web properties - CloudTune application APIs and governed workflow surfaces - Authentication, authorization, evidence integrity, and export boundaries that are reachable in supported deployments ## Out of scope - Social engineering, phishing, or physical attacks - Denial-of-service testing, automated volumetric scanning, or destructive load testing - Reports that require access to another customer's data without evidence of a boundary failure - Issues in third-party services that CloudTune does not control unless the report shows a CloudTune-specific integration flaw ## Researcher expectations - Do not exfiltrate, modify, or destroy customer data. - Stop once you have enough evidence to demonstrate the issue. - Do not run persistence, lateral movement, or privilege-escalation steps beyond what is necessary to prove the bug. - Give CloudTune a reasonable remediation window before public disclosure. ## CloudTune commitments - CloudTune will acknowledge receipt of a credible report. - CloudTune will triage the report, determine severity, and route it through the security incident process when needed. - CloudTune will not treat a good-faith report that follows this policy as an authorized destructive test or a bug bounty claim. ## Compensation boundary CloudTune does not currently run a public bug bounty program. Submission of a report through this policy does not imply payment, automatic reward, or managed researcher status.