Cloud Security Alliance Security and Vulnerability Reporting
security.txt:
Contact: security@cloudsecurityalliance.org Expires: 2050-01-01T08:01:00.000Z Prefered-Languages: en Canonical: https://cloudsecurityalliance.org/.well-known/security.txt Policy: https://cloudsecurityalliance.org/security
What is in scope for security reports:
ccak.training
ccsk.training
cloudbytesconnect.com
cloudcert.org
cloudsecurityalliance.ai
cloudsecurityalliance.ca
cloudsecurityalliance.cloud
cloudsecurityalliance.cn
cloudsecurityalliance.com
cloudsecurityalliance.dev
cloudsecurityalliance.events
cloudsecurityalliance.ie
cloudsecurityalliance.info
cloudsecurityalliance.io
cloudsecurityalliance.net
cloudsecurityalliance.nl
cloudsecurityalliance.org
cloudsecurityalliance.social
cloudsecurityalliance.training
cloudsecuritycongress.org
csa.support
csaapac.org
csachapter.io
csacloudbytes.com
csacloudthreatssummit.com
csacloudtrustsummit.com
csacongress.com
csacongress.org
csacongress.us
csaemeacongress.com
csaemeasummit.com
csafederalsummit.com
csafincloudsecsummit.com
csaresearchsummit.com
csasummitrsac.com
csazerotrustsummit.com
cxotrustsummit.com
gsd.id
sdp.training
sectember.com
sectember.events
star.watch
webfinger.io
working-group-cloudsecurityalliance.org
zta.training
What is out of scope for security reports:
- github.com/cloudsecurityalliance/* (please file an issue in GitHub or check the SECURITY.MD for specifics)
- cloudsecurityalliance.auth0.com/* (please file an issue with Auth0 at https://auth0.com/responsible-disclosure-policy)
- Any "best practices" for SPF/DKIM/DMARC/BIMI/TLS/HTTP HEADERS
How to report security reports:
security@cloudsecurityalliance.org, we accept plaintext email, we do not use a GPG/PGP key at this time.
Bug Bounty:
We are a non-profit organization, as such, we do not provide monetary rewards for vulnerability reports.
Acknowledgements:
We do not provide acknowledgements at this time.