Check my claim, free Deadline running out

Or message us on Telegram @personalchargeback

We welcome reports of security vulnerabilities in systems operated by Personal Chargeback Ltd. This policy explains what is in scope, how to report, and what you can expect from us.

Scope

In scope: this website and its subdomains, and our public-facing corporate infrastructure. Out of scope: any client system, any third-party service we use but do not operate, and any system not listed above. Testing a client system is not covered by this policy and would be unlawful.

What we ask

  • Report privately to security@cipherline.example before disclosing anywhere else.
  • Give us enough detail to reproduce the issue, a proof of concept, request and response, or short video.
  • Limit testing to what is necessary to demonstrate the issue. Do not access, modify or delete data belonging to others.
  • Do not run denial-of-service testing, spam, social engineering against our staff, or physical intrusion attempts.
  • Give us 90 days to remediate before public disclosure, and coordinate the timing with us.

What you can expect

  • Acknowledgement within 2 working days of your report reaching us.
  • A triage assessment within 5 working days, including our view of severity and whether we consider it in scope.
  • Regular updates at least every 14 days until the issue is resolved.
  • Credit in our acknowledgements, if you would like it and the report is valid.
  • An honest answer if we disagree that something is a vulnerability, with our reasoning.

We do not currently operate a paid bug bounty. We are a consultancy rather than a product company, and we would rather be straightforward about that than imply a reward that does not exist.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue or support legal action against you in relation to it, and we will work with you if a third party raises a concern about your activity in our scope. Good faith means: staying within scope, avoiding privacy violations and service degradation, not exfiltrating data beyond the minimum needed to demonstrate the issue, and reporting promptly.

This safe harbour applies only to systems we operate. It cannot and does not authorise testing of any client system.

Our own disclosure practice

Where our consultants discover a vulnerability in third-party software during a client engagement, we follow coordinated disclosure: the vendor is notified privately, given 90 days to remediate, and credited. We never publish details of a client environment, and any public write-up is anonymised and requires written client approval.

Contact

security@cipherline.example. PGP key available on request.

Newsletter

Know your rights before you need them

A short monthly email on consumer money rights: what changed, what it means, and the deadlines worth putting in a diary. No sales pitches, and never more than twelve a year.

You are subscribed.

Look out for the next email at the start of the month.