Security

Found something? Tell us.

We would rather hear it from you than read about it later. This policy is what /.well-known/security.txt points at.

How to report

Email [email protected] with what you found, how to reproduce it, and what you think the impact is. You will get a human acknowledgement within two business days and a resolution target within five.

In scope

  • cio.cafe and any subdomain we operate.
  • Anything that could expose member information, application content or email addresses.
  • Anything that lets someone impersonate CIO Cafe.

Out of scope

  • Findings from automated scanners with no demonstrated impact.
  • Missing headers or best-practice suggestions with no exploit path. Tell us anyway — just do not expect a bounty.
  • Social engineering of our members or staff, and any physical attack.
  • Denial of service, volumetric testing, or anything that degrades the service for members.

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research. Stay within scope, stop as soon as you have proof, do not access or modify anyone else’s data, and give us reasonable time to fix it before publishing.

Bounty

There is no paid bounty programme today. We will credit you by name on this page if you want that, and we will say plainly what you found. Owner: revisit once there is a budget line for it

Our own posture

cio.cafe is a static site: no database, no login, no user-generated content, and no member data stored in the web root. The current known gaps and what is being done about them are listed in the trust centre, because publishing only the good half would defeat the point.