Vulnerability Disclosure Policy
The security of our platform and our customers' financial data is our top priority. We welcome good-faith reports from security researchers and will work with you to verify and fix any issue.
Report a vulnerability arrow_forwardIn scope
- All *.cdhsecurities.com web domains and subdomains
- The CDH Securities investor web app and admin portal
- CDH Securities mobile applications (iOS & Android)
- Public CDH Securities APIs and services
Out of scope
- Physical attacks against offices, staff or hardware
- Social engineering of staff, customers or partners
- Denial-of-service (DoS/DDoS) and volumetric/load testing
- Phishing or spam, and automated scanner output without a working exploit
- Self-XSS, missing security headers or missing CAPTCHA without a demonstrated impact
- Clickjacking on pages with no sensitive action
- Issues requiring physical access to a victim's unlocked device
- Best-practice suggestions without an exploitable vulnerability
How to report
Email your findings to security@cdhsecurities.com. Please include:
- arrow_rightA clear description of the vulnerability
- arrow_rightStep-by-step reproduction instructions
- arrow_rightAffected URLs, endpoints or screens
- arrow_rightProof-of-concept (code, requests or screenshots)
- arrow_rightThe potential impact
- arrow_rightYour preferred contact details
Please do
- checkTest only accounts you own or are explicitly authorised to test
- checkStop and report immediately if you access another user's data
- checkKeep findings confidential until we confirm they are resolved
- checkGive us reasonable time to remediate before any public disclosure
Please don't
- closeAccess, modify, download or delete data that isn't yours
- closeDegrade, interrupt or damage our systems or services
- closeViolate the privacy of our customers or staff
- closeUse findings for extortion or any unlawful purpose
What to expect
We acknowledge receipt of your report.
We complete an initial assessment and triage severity.
We keep you updated through remediation.
We confirm the fix and, with your permission, credit you.
Safe harbour & recognition
We do not currently run a paid bug-bounty programme. However, if you make a good-faith effort to follow this policy, we will not pursue or support legal action against you, and we are happy to publicly credit you (with your permission) for valid, responsibly disclosed reports. Please act in good faith, avoid privacy violations and data destruction, and give us reasonable time to remediate.