CST-360 — Protecting what matters

Report a vulnerability

We are a security company. If you find a weakness in something we run, we would rather hear it from you than from an incident.

How to reach us

Send your report through our contact page and mark it as a security report. Please include:

  • The affected URL, endpoint or asset
  • Steps to reproduce, and what you observed
  • Why you believe it is exploitable, and the impact you think it has
  • Any proof-of-concept material — please keep it minimal

What is in scope

  • cst-360.com and its subdomains that we operate
  • Publicly reachable services we host

What is out of scope

  • Third-party services we merely link to or embed — the scheduling service, for example. Report those to their operators.
  • Our clients' systems. Nothing on this page authorises testing against any client of ours.
  • Findings that require no realistic attacker capability: missing hardening headers with no demonstrated impact, automated-scanner output without a working path to exploitation, denial of service, social engineering, or physical access.

How to test responsibly

We ask that you:

  • Stay within the scope above, and stop as soon as you have a proof of concept
  • Do not access, modify or exfiltrate data that is not yours — if you encounter personal data, stop and tell us
  • Do not degrade service availability, and do not run destructive tests
  • Give us reasonable time to remediate before publishing

What you can expect from us

  • Acknowledgement within one business day
  • An initial assessment — whether we can reproduce it, and our severity view — within five business days
  • Progress updates until the issue is closed
  • Credit where you want it, once the fix has shipped
  • We will not pursue legal action over good-faith research that follows this page

No bounty

We do not currently run a paid bug-bounty programme. Reports are handled on the terms above, and we are genuinely grateful for them.

Machine-readable policy

This page is the human-readable version. A security.txt file will be published at /.well-known/security.txt pointing here.