ChaptersEventsBlog
Register for DataSecAI 2025 in Dallas – Protect Data, Secure AI, and Drive Innovation

Cloud Security Alliance Security and Vulnerability Reporting

security.txt:

Contact: [email protected]
Expires: 2050-01-01T08:01:00.000Z
Prefered-Languages: en
Canonical: https://cloudsecurityalliance.org/.well-known/security.txt
Policy: https://cloudsecurityalliance.org/security


What is in scope for security reports:

ccak.training

ccsk.training

cloudbytesconnect.com

cloudcert.org

cloudsecurityalliance.ai

cloudsecurityalliance.ca

cloudsecurityalliance.cloud

cloudsecurityalliance.cn

cloudsecurityalliance.com

cloudsecurityalliance.dev

cloudsecurityalliance.events

cloudsecurityalliance.ie

cloudsecurityalliance.info

cloudsecurityalliance.io

cloudsecurityalliance.net

cloudsecurityalliance.nl

cloudsecurityalliance.org

cloudsecurityalliance.social

cloudsecurityalliance.training

cloudsecuritycongress.org

csa.support

csaapac.org

csachapter.io

csacloudbytes.com

csacloudthreatssummit.com

csacloudtrustsummit.com

csacongress.com

csacongress.org

csacongress.us

csaemeacongress.com

csaemeasummit.com

csafederalsummit.com

csafincloudsecsummit.com

csaresearchsummit.com

csasummitrsac.com

csazerotrustsummit.com

cxotrustsummit.com

gsd.id

sdp.training

sectember.com

sectember.events

star.watch

webfinger.io

working-group-cloudsecurityalliance.org

zta.training

What is out of scope for security reports:

  • github.com/cloudsecurityalliance/* (please file an issue in GitHub or check the SECURITY.MD for specifics)
  • cloudsecurityalliance.auth0.com/* (please file an issue with Auth0 at https://auth0.com/responsible-disclosure-policy)
  • Any "best practices" for SPF/DKIM/DMARC/BIMI/TLS/HTTP HEADERS
How to report security reports:

[email protected], we accept plaintext email, we do not use a GPG/PGP key at this time.

Bug Bounty:

We are a non-profit organization, as such, we do not provide monetary rewards for vulnerability reports.

Acknowledgements:

We do not provide acknowledgements at this time.