CyberKreuz encourages responsible reporting of vulnerabilities affecting its systems. Researchers should avoid privacy violations, service disruption, social engineering, persistence, data destruction and access beyond what is necessary to demonstrate a finding.

Reports should include the affected asset, reproducible steps, impact assessment and safe supporting evidence. CyberKreuz will acknowledge valid submissions, investigate in good faith and coordinate remediation and disclosure timing. This policy does not authorize testing of third-party systems or activities prohibited by law.