Vulnerability Disclosure Program (VDP)

Our Vulnerability Disclosure Program (VDP)
Cubbit, in collaboration with Unguess Security, operates a Public Vulnerability Disclosure Program (VDP), open to all security researchers, dedicated to continuously improving the security of our geo-distributed cloud storage services.
We believe in working closely with the security research community. That's why we rely on the Unguess platform to manage the entire vulnerability reporting and evaluation process in a structured and professional way.
Important: all reports must be submitted exclusively through the Unguess platform. Cubbit does not review or process reports received via email, contact forms, social media, or any other direct channel: please do not contact us outside of Unguess.
How it works
Found something interesting?
Submit your report via Unguess → Join the Cubbit VDP on Unguess
Please note: Cubbit does not review or process vulnerability reports submitted via email, contact forms, or any other direct channel.
Reports submitted outside the Unguess platform:
- will not be reviewed
- will not be processed
- will not be eligible for any reward
Safe Harbor
Cubbit considers security research carried out in good faith, in compliance with this program's rules and the scope defined on this page, to be authorized activity. We will not pursue legal action or report to authorities researchers who:
- operate strictly within the scope and rules described on this page;
- test only against their own accounts or data, without accessing, modifying, or exfiltrating other users' data;
- do not disrupt or degrade the availability of Cubbit's services;
- report the vulnerability promptly and exclusively through the Unguess platform, without publicly disclosing it before it has been resolved (responsible disclosure);
- in the event of accidental access to data that is not their own, immediately stop testing and report it to the team right away.
This authorization applies exclusively to activities carried out within the scope of this program and does not cover third-party activity or conduct that violates other applicable laws. Cubbit reserves the right to assess each researcher's good faith on a case-by-case basis.
What's included (Scope)
The programme covers:
- Cubbit DS3 Cloud & Composer web interface
- Exposed REST APIs
- The following endpoints:
We reserve the right to update the list of assets at any time.
What's excluded (Out of Scope)
Not included in the programme:
- cubbit.io and related landing pages
- Cubbit Cell
- Social engineering, phishing, or direct attacks against employees
- Load testing, DoS/DDoS, or any activity that may degrade the service
- Mass account creation
- Theoretical vulnerabilities without demonstrable impact
Rewards
Cubbit may, at its sole discretion, grant a monetary reward for eligible reports. Rewards are not guaranteed, even for valid vulnerabilities. Where a reward is granted, its amount will be determined based on severity, demonstrated impact, the quality of the report, and other relevant factors. Critical vulnerabilities may be eligible for rewards of up to €3,000.
In the case of duplicate reports, only the first valid and reproducible report received through Unguess will be considered eligible (at Cubbit's discretion).
Thank you to all researchers who collaborate responsibly to make Cubbit ever more secure!
