Safe Harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorized, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. This policy is designed to be compatible with responsible, coordinated disclosure.
Scope
Please keep your research within scope. When in doubt, ask us first.
In Scope
- The ccdc.x1000.ai website and its subdomains that we operate
- Authentication, session, and access-control flaws
- Injection, XSS, SSRF, and similar web weaknesses
- Sensitive-data exposure and security misconfiguration
Out of Scope
- Denial-of-service (DoS/DDoS) or volumetric/load testing
- Social engineering of our staff, users, or vendors
- Physical attacks, or testing third-party services we do not operate
- Automated scanner output without a demonstrated, validated impact
How to Research Responsibly
These guidelines keep researchers, our users, and our systems safe.
Make a good-faith effort to avoid privacy violations, data loss, and service disruption
Only interact with accounts you own or have explicit permission to access
Stop and report immediately if you encounter sensitive data
Give us reasonable time to remediate before any public disclosure
Our Response Process
Coordinated disclosure works best when both sides know the steps.
Acknowledge
We aim to confirm receipt of your report within 3 business days.
Triage
We validate, reproduce, and assess the severity of the issue.
Remediate
We fix confirmed issues and keep you informed of progress.
Credit
With your consent, we are happy to acknowledge your contribution.