Security
Found something? Tell us.
We would rather hear it from you than read about it later. This policy is what /.well-known/security.txt points at.
How to report
Email [email protected] with what you found, how to reproduce it, and what you think the impact is. You will get a human acknowledgement within two business days and a resolution target within five.
In scope
- cio.cafe and any subdomain we operate.
- Anything that could expose member information, application content or email addresses.
- Anything that lets someone impersonate CIO Cafe.
Out of scope
- Findings from automated scanners with no demonstrated impact.
- Missing headers or best-practice suggestions with no exploit path. Tell us anyway — just do not expect a bounty.
- Social engineering of our members or staff, and any physical attack.
- Denial of service, volumetric testing, or anything that degrades the service for members.
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research. Stay within scope, stop as soon as you have proof, do not access or modify anyone else’s data, and give us reasonable time to fix it before publishing.
Bounty
There is no paid bounty programme today. We will credit you by name on this page if you want that, and we will say plainly what you found. Owner: revisit once there is a budget line for it
Our own posture
cio.cafe is a static site: no database, no login, no user-generated content, and no member data stored in the web root. The current known gaps and what is being done about them are listed in the trust centre, because publishing only the good half would defeat the point.