Here's how CyberGrid handles your data, the principles we apply to our own infrastructure, and how to report a vulnerability if you find one in us.
The data CyberGrid stores about your organization, your targets, and your findings.
Every target is verified via a DNS TXT record before any scan runs. Every pen-test engagement requires a signed Statement of Work and rules-of-engagement document.
The hosting and platform choices we made — chosen for security, simplicity, and verifiability.
How we run the business day-to-day.
We sell security testing. If you find a vulnerability in CyberGrid itself, please tell us — confidentially — and we'll act on it.
Report to: security@thecybergrid.com
We don't currently run a paid bug-bounty program. We do credit responsible reporters publicly and reply quickly. Please don't run automated scans against our production infrastructure without prior coordination at the email above.