How to report a security problem to us, and what protection you have when you do.
Last updated: September 1, 2026
Email team@cyberexchange.ai with the subject line Security. Tell us what you found, where, and enough detail for us to reproduce it — the request or steps, what you expected, and what happened. Include your name or handle if you would like credit.
Please report to us first and give us a reasonable opportunity to fix the problem before disclosing it publicly.
If you make a good-faith effort to follow this policy, we will treat your research as authorised conduct. We will not pursue or support legal action against you for it, and we will not report it to law enforcement. If someone else brings a claim against you for research that followed this policy, tell us and we will make clear that it was authorised.
This protection covers the research; it does not cover anything you do with data you encounter along the way.
Follow all of these. Research that steps outside them is not covered by the safe harbour above.
In scope: the CyberExchange web application and the interfaces we publish, at cyberexchange.ai. Out of scope: anything operated by a third party, and findings that depend on an out-of-date browser, on a user being already compromised, or on physical access to a device.
Reports with no demonstrated security impact — missing headers, banner disclosure, results from an automated scanner with nothing behind them — are unlikely to be actioned.
We read every report. We will confirm receipt and tell you what we intend to do about it. We do not run a bug bounty and do not offer payment, and we do not commit to a response or remediation deadline — we would rather say that plainly than publish a target we cannot hold to. We are happy to credit you when a report leads to a fix, if you want that.
The Acceptable Use Policy prohibits probing and testing the Service. This policy is the exception to it: research that follows the rules above is permitted. Research that does not is a breach of that policy and of the Terms.
For any question about these documents — including a privacy request, a security report, a copyright or accuracy complaint, or a billing dispute — write to us. One address reaches us for all of it.
IT-Harvest, LLC
Email: team@cyberexchange.ai
Website: it-harvest.com
Notices: 850 New Burton Rd., Suite 201, Dover, Delaware 19904, Kent County