Ethics and disclosure
We teach the attack so more people can defend.
Everything shown on CypherWarden is done on authorised targets: labs, CTFs, our own systems, bug bounty programs within their scope, or vulnerabilities already disclosed and fixed. These rules apply to every video, every write-up and every resource on this site.
Out of bounds
What we never do.
- Testing a system without written permission from its owner, even "just to check".
- Going beyond a bug bounty scope, or ignoring its rules on automation, rate or data.
- Keeping, publishing or using personal data met during a test. We stop at the proof.
- Showing an unfixed vulnerability, or naming a program that does not allow it.
- Shipping ready-to-use malware, phishing kits or tools built to cause harm.
Coordinated disclosure
From finding to video, in four steps.
Report
The finding goes to the owner first, through their program or their security contact. Never to social media.
Fix
We wait for the fix and help verify it. If a vendor does not answer, we follow a 90-day coordinated disclosure deadline.
Permission
Publication needs the program's go-ahead. Some reports are never published, and that is fine.
Publication
The video and the write-up show the attack, then the defence. Identifying details that are not needed are removed.
Report to us
Found a flaw in this site?
Thank you. Write to us with the affected URL, the steps to reproduce and the impact you observed. Test only with your own account, do not access other people's data, and do not run automated scans that degrade the site. We answer within five working days and credit you here if you wish.
This is a personal site with no paid bounty. Good-faith research that follows these rules will not lead to any complaint from us.