generated: '2026-08-04' method: searched probe: true source: https://www.cybrary.it/responsible-disclosure-program program: Cybrary Vulnerability Disclosure Policy type: vulnerability-disclosure-policy bug_bounty: false policy: - https://www.cybrary.it/responsible-disclosure-program - https://hackerone.com/cybrary contact: - report@cybrary.it platforms: - name: HackerOne url: https://hackerone.com/cybrary http_status: 200 kind: vulnerability-disclosure-policy safe_harbor: >- The policy states that if legal action is initiated by a third party against a researcher who has complied with the policy, Cybrary will take reasonable steps to make it known that the researcher's actions were conducted in compliance with the policy. security_txt: null security_txt_note: >- /.well-known/security.txt returns 404 on www.cybrary.it. The disclosure policy is published as an HTML page only; there is no RFC 9116 machine-readable pointer to it. evidence: - source: https://www.cybrary.it/responsible-disclosure-program http_status: 200 kind: disclosure-policy-page fetched: '2026-08-04' keywords: [vulnerability disclosure policy, security researchers, responsible disclosure, report@cybrary.it] - source: https://hackerone.com/cybrary http_status: 200 kind: hackerone-program fetched: '2026-08-04' - source: https://bugcrowd.com/engagements/cybrary http_status: 404 kind: bugcrowd-program fetched: '2026-08-04' note: referenced by third-party search results but not reachable on probe x-note: >- The mechanical probe (0-working/probe-security-programs.py) reported vdp=none because Cybrary publishes the policy at /responsible-disclosure-program, a path outside the probe's candidate list. This file is the SEARCHED upgrade and must not be overwritten by a later probe pass.