CyberProva transparency
Report a security vulnerability
How to report a suspected CyberProva vulnerability responsibly, and the boundaries for security research.
Send a private report
Report suspected vulnerabilities affecting CyberProva to security@cyberprova.com with the subject Security vulnerability report. Do not include passwords, live credentials or other customers' personal data.
- Describe the affected URL or feature, potential impact and the smallest safe set of reproduction steps.
- Include the time of your observation and redacted screenshots or request details where helpful.
- Use a test account and data you own. Stop if you unexpectedly encounter another customer's data and report the circumstances without retaining or sharing it.
Research boundaries
This reporting policy is not blanket authorisation to test production systems or third-party services. Contact us first if proposed testing could affect other users or service availability.
- Do not access, modify, delete or extract another person's data.
- Do not conduct denial-of-service, social engineering, credential attacks or bulk automated scanning.
- Do not test Microsoft, Stripe, customer tenants or other third-party systems under this policy.
- Share the report privately and coordinate any public disclosure with CyberProva so users can be protected.
What to expect
CyberProva can use the report to investigate and coordinate remediation. This is a responsible-reporting channel, not a paid bug bounty programme.
- Include a reply address so we can ask for clarification.
- No response deadline, reward or legal safe-harbour commitment is promised by this page.