Vulnerability disclosure policy

Last reviewed: 27 August 2026

We would rather hear about a security problem from you than from an incident. This page tells you how to report one and what we will do about it.

A machine-readable version of this contact information is published at /.well-known/security.txt, per RFC 9116.

How to report

Email info@cisotimes.com with “Security” in the subject line.

Useful reports include:

  • The affected URL or component.
  • What an attacker could achieve.
  • Enough detail to reproduce it — steps, a request, a proof of concept.
  • Whether you believe any data was exposed.

Please report in English or Greek.

What we will do

Acknowledge your reportWithin 3 working days
Tell you our assessmentWithin 10 working days
Fix what we acceptAs quickly as the severity warrants
Credit youOn request, once it is fixed

We are a small publication, not a vendor with a security team. We do not operate a paid bug bounty and cannot offer a reward. We will tell you honestly and promptly what we intend to do.

Scope

In scope

  • cisotimes.com and its subdomains that we operate.
  • The published website, its forms and its API endpoints.

Out of scope

  • Findings in third-party services we merely use — report those to Cloudflare or Google directly.
  • Reports generated solely by an automated scanner, with no demonstrated impact.
  • Missing hardening headers or configuration preferences with no exploitable consequence.
  • Social engineering of our people, physical attacks, and denial of service.
  • Spam, or content you disagree with. Editorial complaints belong in corrections.

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research.

Good faith means: stop at proof, do not access or modify anyone else’s data, do not degrade the service for other readers, do not use a finding to obtain anything, and give us a reasonable opportunity to fix the issue before you publish.

This is our commitment. It cannot bind third parties, and it is not a waiver of anyone else’s rights.

Disclosure

We ask for 90 days before public disclosure, or sooner once a fix is live and you have confirmed it. If we go quiet on you, publish — a policy that lets us stall indefinitely is not a policy.