Vulnerability disclosure policy
Last reviewed: 27 August 2026
We would rather hear about a security problem from you than from an incident. This page tells you how to report one and what we will do about it.
A machine-readable version of this contact information is published at /.well-known/security.txt, per RFC 9116.
How to report
Email info@cisotimes.com with “Security” in the subject line.
Useful reports include:
- The affected URL or component.
- What an attacker could achieve.
- Enough detail to reproduce it — steps, a request, a proof of concept.
- Whether you believe any data was exposed.
Please report in English or Greek.
What we will do
| Acknowledge your report | Within 3 working days |
| Tell you our assessment | Within 10 working days |
| Fix what we accept | As quickly as the severity warrants |
| Credit you | On request, once it is fixed |
We are a small publication, not a vendor with a security team. We do not operate a paid bug bounty and cannot offer a reward. We will tell you honestly and promptly what we intend to do.
Scope
In scope
cisotimes.comand its subdomains that we operate.- The published website, its forms and its API endpoints.
Out of scope
- Findings in third-party services we merely use — report those to Cloudflare or Google directly.
- Reports generated solely by an automated scanner, with no demonstrated impact.
- Missing hardening headers or configuration preferences with no exploitable consequence.
- Social engineering of our people, physical attacks, and denial of service.
- Spam, or content you disagree with. Editorial complaints belong in corrections.
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research.
Good faith means: stop at proof, do not access or modify anyone else’s data, do not degrade the service for other readers, do not use a finding to obtain anything, and give us a reasonable opportunity to fix the issue before you publish.
This is our commitment. It cannot bind third parties, and it is not a waiver of anyone else’s rights.
Disclosure
We ask for 90 days before public disclosure, or sooner once a fix is live and you have confirmed it. If we go quiet on you, publish — a policy that lets us stall indefinitely is not a policy.