Adrian De Gendt
CYBRET AI
August 2026
Last updated: August 21, 2026 · Ethira AB
Email security@ethira.dev. Do not open a public GitHub issue, post on social media, or discuss the issue with anyone outside Ethira until we have resolved it or agreed a disclosure date with you.
Include:
Encrypt the report if it contains customer data or credentials. We do not currently publish a PGP key; describe live secrets rather than attaching them.
This is a coordinated disclosure programme, not a paid bug bounty. Significant in-scope findings are credited on our Hall of Fame, with a stable link you can cite. Tell us the name you want listed.
In scope
Out of scope
Test only against accounts and workspaces you own or that we have explicitly authorised.
If you find a way to access another customer's data, stop. Do not exfiltrate, modify, or persist that data. Note enough to demonstrate the issue and email us.
Do not:
If you follow this policy in good faith, Ethira will not pursue legal action against you or ask law enforcement to do so for the research described in your report. This is not a licence to attack systems outside the scope above, to access other customers' data beyond what is needed to demonstrate an issue, or to violate applicable law.
If you are unsure whether a test is allowed, email security@ethira.dev first.
Please hold off on public disclosure until we have had time to investigate and ship a fix. We will agree timing with you. If we cannot meet a date you have in mind, we will say so and explain why.
Researchers whose reports led to a security fix, listed here with their consent. Each name has a permanent link you can cite. We publish the name, affiliation, and date — never what was found.
CYBRET AI
August 2026
Reserved
The next name goes here
Named with your consent, after a fix ships.