File Systems and Communication
All access to Cyber Skyline is restricted to HTTPS encrypted connections.
Cyber Skyline never collects or stores passwords for external applications like GitHub, Google, etc. Integration with third-party apps is done via either OAuth or API keys.
Server Location
All core servers are hosted on Amazon Web Services within the region of United States. Cyber Skyline databases & replicas are securely hosted by MongoDB's SOC2 & GDPR compliant infrastructure, see MongoDB Trust Center. If your organization has a dedicated deployment of Cyber Skyline's platform, please refer to the specific terms of service within your organization.
Credit Card Safety
Cyber Skyline handles payments using a trusted payment processor company called Stripe. User-supplied credit card information is sent directly to and stored on Stripe's secure PCI-certified infrastructure. Stripe is certified to PCI Service Provider Level 1, the most stringent level of certification available. Cyber Skyline does not at any point store or transmit your credit card numbers. Cyber Skyline communicates with Stripe using secure tokens to avoid reading or transmitting sensitive user information. To learn more about Stripe's security, please visit the Security at Stripe page.
Vulnerability Disclosure
Please send an email to security@cyberskyline.com to report a vulnerability.
Disclosure Policy
- Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
- Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.
- All tests against endpoints that require user/email information must be associated with an account or email of your HackerOne email alias in the form of
[username]@wearehackerone.comor[username]+[any_identifier]@wearehackerone.com. If you are not a HackerOne user, please use an email with thesecuritytestingidentifier such as[username]+securitytesting@[domain].
Exclusions
While researching, we'd like to ask you to refrain from:
- Denial of service
- Spamming
- Excessively bruteforcing endpoints
- Social engineering (including phishing) of Cyber Skyline staff/contractors or other Cyber Skyline users
- Any actions that will severely limit the use of Cyber Skyline platform for other users
- Any physical attempts against Cyber Skyline property, data centers, or other Cyber Skyline users' properties
Safe Harbor
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Additional
If you believe you may have discovered a very critical security vulnerability but testing it could potentially disrupt service for other users, we encourage you to get in touch with us ASAP and we can provide a staging environment for testing purposes.
This Vulnerability Disclosure Policy may not be the latest version, for the latest version of our Vulnerability Disclosure Policy as well as additional details, please email us at security@cyberskyline.com to join our HackerOne program.