Help Us Stay Safe & Secure
Cytrusst invites security researchers to responsibly find and report vulnerabilities across our platform. Your discoveries make our GRC, ASM and Cloud Security products stronger for every enterprise we protect.
Reward Tiers
Rewards scale with the severity and impact of your finding. Every valid report earns recognition.
- Hall of Fame #1 spotlight
- Premium goodies pack
- Hall of Fame listing
- Goodies pack
- Hall of Fame Listing
- Digital certificate
- Digital certificate
How to Report
Follow these simple steps to report a vulnerability. We'll take care of the rest.
Find & Document
Record the exact steps, capture screenshots, and clearly describe the security impact of the issue.
Write a clear PoC
Provide reproducible HTTP requests, payloads, and any code needed to verify the vulnerability.
Email your report
Send your complete write-up to both security contacts listed below. We respond within 48 hours.
Submit a Report
Hall of Fame
| Researcher | Target | Finding | Year | Severity |
|---|---|---|---|---|
| Kavin Nagaraj | api.cytrusst.com | Command injection | 2026 | Critical |
| Kavin Nagaraj | api.cytrusst.com | SQL injection | 2026 | High |
| Kavin Nagaraj | api.cytrusst.com | XSS | 2026 | Medium |
Program Rules
Clear, reproducible reports required
Every submission needs steps, a PoC, and a clear impact statement.
No aggressive automated scanning
Avoid high-volume scanners and any traffic that degrades service.
Test only in-scope targets
Restrict all testing to cytrusst.com and listed assets.
No social engineering
Phishing, physical attacks, and targeting staff are out of scope.
Keep findings confidential until fixed. Do not disclose publicly before we confirm a fix has shipped.
Never access, alter, or exfiltrate user data. Use only test accounts.
Terms and Conditions
Responsible Disclosure Terms & Guidelines
By participating in the Cytrusst Responsible Disclosure Program, you agree to the following:
- Do not modify, delete, or misuse customer or user data without prior written authorization.
- Do not perform testing that disrupts services or negatively affects other users.
- Keep all vulnerability information confidential and do not disclose it publicly without Cytrusst's written approval.
- Do not exploit any discovered vulnerability for personal gain.
- Immediately notify Cytrusst if any inadvertent exposure of sensitive information occurs.
- Allow Cytrusst a reasonable amount of time to investigate and remediate reported vulnerabilities before any public disclosure.
- Comply with all applicable laws and regulations during security research.
- Provide sufficient technical details, including reproduction steps and proof of concept, to help validate and remediate the issue.
- Assist with clarification or mitigation if requested by the Cytrusst security team.
Submission of a vulnerability report constitutes acceptance of these Responsible Disclosure Guidelines. Any violation of these terms may result in removal from the program and appropriate legal action where applicable.
Out of Scope Targets
All external services, software, or infrastructure not owned, managed, or controlled by Cytrusst are considered out of scope and are not eligible for recognition.
Out of Scope Vulnerabilities — Web
The following issues are considered out of scope unless accompanied by a demonstrable security impact:
- SPF, DMARC, or DKIM misconfigurations without verifiable email spoofing.
- Best practice issues such as: Cookies not marked Secure or HttpOnly (when non-sensitive), Missing security headers, SSL/TLS configuration recommendations.
- Reports generated solely by automated scanners without a valid Proof of Concept.
- Issues affecting End-of-Life browsers (e.g., Internet Explorer 6).
- Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.
- Vulnerabilities requiring physical access to a victim's device.
- Host Header Injection.
- Unauthenticated, login, or logout CSRF.
- Reports involving outdated or vulnerable libraries without a working exploit.
- Email spoofing, phishing attacks, fake login pages, or credential harvesting.
- Self-XSS.
- Social engineering attacks requiring unrealistic user interaction.
- Third-party API keys intended to be public or exposed Android XML keys without security impact.
- Enabled HTTP OPTIONS or TRACE methods.
- Disclosure of public files or directories (robots.txt, CSS, images, etc.).
- Browser autocomplete or password-saving functionality.
- Vulnerabilities requiring browser extensions or additional software on the victim's device.
- Brute-force attacks against non-sensitive forms (e.g., Contact Us, Newsletter).
- Missing Content Security Policy best practices.
- Missing SSL certificates or CAA records.
- Functional, UI/UX, cosmetic, or spelling issues.
Cytrusst · Safe & Secure · Bug Bounty Program
© 2026 Cytrusst Intelligence Private Limited. All rights reserved.