Security
Report a vulnerability.
We'd rather hear it from you than find out the hard way. Thank you for looking.
How to report
Email security@bestcyber.co with a description of the issue, the steps to reproduce it, and what an attacker could achieve. Please don't use the contact form for vulnerability reports.
In scope
- This website and its administration area
- The Scouter endpoint agent and the Mesh console
What to expect
- An acknowledgement within three business days.
- An honest assessment of the issue and a timeline for a fix.
- Credit for your finding, if you'd like it, once it's fixed.
Good faith
If you act in good faith (you avoid privacy violations, data destruction and service disruption, you only access what you need to demonstrate the issue, and you give us reasonable time to fix it before disclosing), we will not pursue or support legal action against you for your research.
Please don't test against our clients' systems, run denial-of-service attacks, or use social engineering or physical attacks. We don't currently run a paid bug bounty.
Our contact details are also published in machine-readable form, in our security.txt file.