Responsible disclosure policy
Last updated
We welcome reports of security vulnerabilities in the systems IMIZI Cyber operates, and we answer every one. This policy sets out what is in scope, how to report, what to expect from us, and the authorisation we give researchers who follow it.
Scope
In scope
imizicyber.comand the subdomains we operate- Other internet-facing services operated by IMIZI Cyber
Out of scope
- Third-party platforms we use. Report issues in these services to the provider directly, through its own disclosure programme: Cloudflare (hosting, content delivery, analytics and Turnstile), Formspree (form handling), Cal.com (booking pages), Google (Google Workspace email), WhatsApp (Meta) (messaging).
- Our clients' systems. This policy never authorises testing of systems that belong to anyone else.
- Scanner output without a demonstrated security impact.
If you are unsure whether something is in scope, ask us first.
How to report
Email security@imizicyber.com. If the report contains sensitive detail, encrypt it with our PGP key and check the fingerprint before you do.
- User ID
- IMIZI Cyber Security <security@imizicyber.com>
- Fingerprint
B7CC 9912 18AF 6638 DDFF E0A1 2715 81DD 9A59 963F- Algorithm
- RSA 4096
- security.txt
- /.well-known/security.txt
Please include:
- A clear description of the vulnerability and where it is
- Steps to reproduce it
- Its potential impact
- Any proof-of-concept code, screenshots or logs
- How we can reach you for follow-up
What to expect
These are our targets for every report:
- Acknowledgement within 3 business days of your report.
- Initial assessment, with a severity rating and next steps, within 5 business days of acknowledgement.
- Updates as the fix progresses, and a note when it is done.
- Coordinated disclosure within 90 days of your report. If a fix needs longer, we explain why and agree a new date with you.
- Credit in the disclosure, if you want it.
Safe harbour
If you make a good-faith effort to follow this policy, we authorise your research on the in-scope systems above, within the rules below. For research that stays within this policy, we will:
- treat it as authorised access to our systems;
- not take or support legal action against you for it;
- make it known that your research was authorised, if anyone else takes action against you over it;
- work with you to understand and fix the issue.
Rwanda's Law N° 60/2018 of 22/08/2018 on prevention and punishment of cyber crimes makes unauthorised access to a computer system an offence. This policy is our written authorisation for research that stays within its scope and rules. It covers only systems IMIZI Cyber owns and operates: we cannot authorise testing of third-party platforms or client systems, and this policy does not bind public authorities or anyone else.
Rules of engagement
- Do not access, change or delete data that is not yours. If you reach personal or client data, stop, do not keep a copy, and tell us straight away.
- Use a vulnerability only as far as you need to demonstrate it.
- No denial-of-service, load or volumetric testing.
- No social engineering, phishing or physical attempts against our staff or premises.
- Give us a reasonable opportunity to fix the issue, and coordinate the disclosure date with us before publishing anything.
- Make a good-faith effort to avoid privacy violations and disruption to our services.
Thank you for helping us keep our systems and our clients secure.