Responsible Disclosure Policy
Effective Date: April 10, 2026 Last Updated: April 10, 2026
Corvus Cybersecurity, a brand of D Shaw Consulting & Training, Inc., takes the security of our systems and website seriously. We appreciate the work of independent security researchers who help identify vulnerabilities responsibly. This policy outlines how to report security issues to us and what you can expect in return.
Scope
This policy applies to security vulnerabilities identified in:
- The Corvus Cybersecurity website (corvus-cyber.com)
- Any subdomains operated by D Shaw Consulting & Training, Inc. (dba Corvus Cybersecurity)
- Client-facing tools or portals operated directly by Corvus
This policy does not apply to systems, networks, or applications owned or operated by our clients. If you believe you have identified a vulnerability in a client environment, contact that organization directly. Corvus does not accept third-party vulnerability disclosures on behalf of our clients.
What We Ask of You
If you discover a potential security vulnerability affecting our systems, we ask that you:
- Report it to us promptly by emailing [email protected] with the subject line “Security Disclosure”
- Provide sufficient detail to allow us to reproduce and assess the issue — including the affected URL or component, steps to reproduce, and any supporting evidence such as screenshots or proof-of-concept code
- Avoid accessing, modifying, or exfiltrating data beyond what is necessary to demonstrate the vulnerability
- Refrain from automated scanning that could degrade service availability or affect other users
- Give us reasonable time to respond before disclosing the issue publicly — we ask for a minimum of 30 days from initial contact
- Act in good faith — do not exploit the vulnerability for any purpose beyond demonstrating its existence to us
What You Can Expect from Us
When you submit a valid vulnerability report, Corvus commits to:
- Acknowledging receipt of your report within 3 business days
- Providing an initial assessment of severity and scope within 10 business days
- Keeping you informed of our remediation progress throughout the process
- Crediting your contribution publicly if you wish, once the issue has been resolved
- Not pursuing legal action against researchers who act in good faith and comply with this policy
Out of Scope
The following are outside the scope of this policy and should not be reported:
- Findings from automated scanners without manual validation
- Denial of service attacks or volumetric testing
- Social engineering or phishing attempts targeting Corvus staff
- Physical security issues
- Vulnerabilities in third-party services or software we do not control
- Issues that require unlikely user interaction or theoretical attack paths with no practical exploit
- SSL/TLS configuration issues that do not present a realistic attack vector
- Missing HTTP security headers that do not lead to demonstrated exploitation
Safe Harbor
Corvus Cybersecurity will not pursue civil or criminal action against security researchers who:
- Discover and report vulnerabilities in accordance with this policy
- Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
- Do not disclose vulnerabilities publicly before we have had a reasonable opportunity to address them
- Do not access, retain, or share any data belonging to Corvus or its clients
We consider responsible disclosure under this policy to constitute authorized access under the Computer Fraud and Abuse Act and applicable state computer crime laws.
How to Report
Send your report to:
Email: [email protected]
Subject line: Security Disclosure
Encryption: PGP encryption is available upon request for sensitive disclosures
Please include:
- A description of the vulnerability and its potential impact
- The affected URL, system, or component
- Step-by-step reproduction instructions
- Any supporting evidence (screenshots, proof-of-concept, HTTP requests/responses)
- Your preferred contact method for follow-up
Recognition
Corvus maintains a record of researchers who have responsibly disclosed valid vulnerabilities. If you would like to be acknowledged publicly, please indicate this in your report and we will credit you by name or handle once the issue is resolved.
D Shaw Consulting & Training, Inc. dba Corvus Cybersecurity · Southern California · corvus-cyber.com