RESPONSIBLE DISCLOSURE

Security

Clear reporting, bounded scope, and no manufactured promises.

Reporting

A dedicated vulnerability-reporting address will be published after the Downum Cyber email-security configuration is active. Until then, do not send sensitive vulnerability details through unverified channels.

Scope

Only the public Downum Cyber website will be in scope when it launches. Private RAGNAROK infrastructure, personal systems, third-party providers, and denial-of-service testing are not authorized targets.

No bounty promise

Downum Cyber does not currently operate a vulnerability bounty program. Good-faith reporting guidance will be expanded as the public surface grows.