ChaptersCircleEventsBlog
Take the Cloud Security & AI Trends Survey for a chance to win a free CCSK token ($445 value) or a CCZT + CCSK training bundle ($1,250 value)!
Security

Cloud Security Alliance Security and Vulnerability Reporting

security.txt:

Contact: security@cloudsecurityalliance.org
Expires: 2050-01-01T08:01:00.000Z
Prefered-Languages: en
Canonical: https://cloudsecurityalliance.org/.well-known/security.txt
Policy: https://cloudsecurityalliance.org/security

What is in scope for security reports:

ccak.training

ccsk.training

cloudbytesconnect.com

cloudcert.org

cloudsecurityalliance.ai

cloudsecurityalliance.ca

cloudsecurityalliance.cloud

cloudsecurityalliance.cn

cloudsecurityalliance.com

cloudsecurityalliance.dev

cloudsecurityalliance.events

cloudsecurityalliance.ie

cloudsecurityalliance.info

cloudsecurityalliance.io

cloudsecurityalliance.net

cloudsecurityalliance.nl

cloudsecurityalliance.org

cloudsecurityalliance.social

cloudsecurityalliance.training

cloudsecuritycongress.org

csa.support

csaapac.org

csachapter.io

csacloudbytes.com

csacloudthreatssummit.com

csacloudtrustsummit.com

csacongress.com

csacongress.org

csacongress.us

csaemeacongress.com

csaemeasummit.com

csafederalsummit.com

csafincloudsecsummit.com

csaresearchsummit.com

csasummitrsac.com

csazerotrustsummit.com

cxotrustsummit.com

gsd.id

sdp.training

sectember.com

sectember.events

star.watch

webfinger.io

working-group-cloudsecurityalliance.org

zta.training

What is out of scope for security reports:

  • github.com/cloudsecurityalliance/* (please file an issue in GitHub or check the SECURITY.MD for specifics)
  • cloudsecurityalliance.auth0.com/* (please file an issue with Auth0 at https://auth0.com/responsible-disclosure-policy)
  • Any "best practices" for SPF/DKIM/DMARC/BIMI/TLS/HTTP HEADERS

How to report security reports:

security@cloudsecurityalliance.org, we accept plaintext email, we do not use a GPG/PGP key at this time.

Bug Bounty:

We are a non-profit organization, as such, we do not provide monetary rewards for vulnerability reports.

Acknowledgements:

We do not provide acknowledgements at this time.