Security
Reporting a security problem.
This page covers internet services clearly operated by CYSTRIKE LTD.
What to include
Include the affected URL or service, the observed behaviour, the likely security effect and the smallest reproducible sequence. Redact credentials, personal information and unrelated customer data. A short request and response is easier to review than an unfiltered capture.
Testing boundary
Ordinary browsing and passive observation do not require prior contact. Before taking any action that changes data, accesses an account, sends a message, affects availability, touches a third party or goes beyond your own systems and records, request written authorisation. Do not use social engineering, persistence, bulk automation or denial-of-service techniques.
If sensitive data appears
Stop. Do not expand access or retain more than the minimum needed to describe the event. Report what appeared, where it appeared and the last safe action taken.
What happens next
Reports are reviewed directly. CYSTRIKE may ask for a clarifying detail or a safe retest after a correction. This page is a reporting route; it is not standing authorisation to test a system.