Responsible Disclosure
Last updated 19 August 2026
We welcome reports of security vulnerabilities in systems operated by Personal Chargeback Ltd. This policy explains what is in scope, how to report, and what you can expect from us.
Scope
In scope: this website and its subdomains, and our public-facing corporate infrastructure. Out of scope: any client system, any third-party service we use but do not operate, and any system not listed above. Testing a client system is not covered by this policy and would be unlawful.
What we ask
- Report privately to security@cipherline.example before disclosing anywhere else.
- Give us enough detail to reproduce the issue, a proof of concept, request and response, or short video.
- Limit testing to what is necessary to demonstrate the issue. Do not access, modify or delete data belonging to others.
- Do not run denial-of-service testing, spam, social engineering against our staff, or physical intrusion attempts.
- Give us 90 days to remediate before public disclosure, and coordinate the timing with us.
What you can expect
- Acknowledgement within 2 working days of your report reaching us.
- A triage assessment within 5 working days, including our view of severity and whether we consider it in scope.
- Regular updates at least every 14 days until the issue is resolved.
- Credit in our acknowledgements, if you would like it and the report is valid.
- An honest answer if we disagree that something is a vulnerability, with our reasoning.
We do not currently operate a paid bug bounty. We are a consultancy rather than a product company, and we would rather be straightforward about that than imply a reward that does not exist.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue or support legal action against you in relation to it, and we will work with you if a third party raises a concern about your activity in our scope. Good faith means: staying within scope, avoiding privacy violations and service degradation, not exfiltrating data beyond the minimum needed to demonstrate the issue, and reporting promptly.
This safe harbour applies only to systems we operate. It cannot and does not authorise testing of any client system.
Our own disclosure practice
Where our consultants discover a vulnerability in third-party software during a client engagement, we follow coordinated disclosure: the vendor is notified privately, given 90 days to remediate, and credited. We never publish details of a client environment, and any public write-up is anonymised and requires written client approval.
Contact
security@cipherline.example. PGP key available on request.