Last Updated: September 18, 2026
Our Commitment to Security
Security is core to our values, and we value the contributions of security researchers acting in good faith to help us maintain a high standard of security and privacy for our users, partners, and employees. This Vulnerability Disclosure Policy (“Policy”) describes how to report a suspected vulnerability to CNote Group, Inc. (“CNote,” “we,” or “us”), what we ask of researchers acting in good faith, and what you can expect from us in return, including the scope of our Safe Harbor protections.
This Policy is not a bug bounty program. CNote does not currently offer monetary rewards for reports submitted under this Policy.
Scope
This Policy covers systems CNote owns and operates. Scope is defined by domain and asset class rather than by hostname.
In Scope
- Any subdomain of mycnote.com or cnotegroup.com, in any environment, including production, staging, or demo, except as excluded below.
- CNote applications and CNote data wherever they run, including on third-party application platforms and at provider-assigned endpoints such as a CDN, load balancer, container platform, API gateway, or object store.
- CNote cloud storage where public access exposes data not intended to be public, or where unauthenticated write access is possible. Some CNote storage intentionally serves public website content; that alone is not a finding.
- Issues reachable without credentials, or with credentials for an account you own.
Out of Scope
- Systems CNote does not operate. Our public marketing website and blog are served by a managed hosting platform we do not run and cannot authorize testing of; the same applies to third-party services on their own domains. Report those to the vendor, and tell us if CNote data is involved. CNote’s own content, configuration, and code on those platforms remain in scope.
- Internal systems. Some CNote hostnames resolve to private, non-internet-routable addresses. Reaching internal networks by VPN, credential reuse, pivoting, SSRF, or any other route is outside this Policy.
- Denial of service, load testing, and resource exhaustion against any CNote system whether or not otherwise in scope.
- Social engineering, phishing, and physical access directed at CNote staff, customers, partners, or facilities.
- Findings that require a compromised device, a malicious browser extension, or a privileged network position.
- Reports with no demonstrated exploitable impact: raw scanner output; email authentication records without a working spoofing demonstration; missing rate limiting; self-XSS; clickjacking on pages carrying no sensitive action; cookie flags on non-session cookies; software version banners.
- Compromises that rely on insider access rather than an external technical vulnerability.
- Account takeover attempts, credential stuffing, or brute-force attacks against any account other than one you own.
- Reflected file download (RFD) findings.
- Dependency hijacking or typosquatting of CNote package or library names.
- Testing that intentionally alters, corrupts, or deletes data belonging to another user.
- Reports of a vulnerability in third-party software CNote uses where a vendor patch has been publicly available for fewer than 30 days, absent evidence of active exploitation.
If It Is Serious and Not Listed Here, Tell Us Anyway
This scope defines what we can authorize you to test. It is not a list of what we want to hear about. If you believe you have found a serious issue affecting CNote systems or CNote customer data, including on a system not named here, report it to us. We will treat it as a good faith disclosure.
How to Report a Vulnerability
Official Channel
Contact us via email at security@mycnote.com with a detailed report of the suspected vulnerability.
Your report should include as much of the following as possible:
- Type of vulnerability;
- Whether the information has been published, shared with others, or otherwise disclosed;
- Affected sites, systems, or configurations;
- Step-by-step instructions or proof-of-concept code sufficient to replicate the issue; and
- Your assessment of severity or impact, and a CVSS score or CWE classification if known (not required).
What You Can Expect From Us
When you submit a report consistent with this Policy, you can expect us to:
- Work in good faith to understand and validate your report;
- Work to remediate confirmed vulnerabilities in a timeframe appropriate to their severity, and communicate with you about our remediation timeline where appropriate;
- Extend Safe Harbor for security research conducted consistent with this Policy; and
- With your permission, attribute your name and contribution on any public disclosure we make, to the extent we choose to make a public disclosure.
Ground Rules
To encourage vulnerability research and to avoid any confusion between good faith research and malicious activity, we ask that you:
- Play by the rules, including this Policy and any other relevant agreements. If there is any inconsistency between this Policy and any other applicable terms, this Policy governs for activity conducted in accordance with it;
- Report any vulnerability you discover promptly, and avoid disclosing it to others until it has been resolved consistent with our Disclosure Policy below;
- Avoid violating the privacy of others, disrupting our systems or those of our users, destroying data, or degrading user experience;
- Use only the Official Channel described above to discuss vulnerability information with us;
- Perform testing only on in-scope systems, and respect systems and activities that are out of scope;
- Only interact with test accounts you own, or with the explicit permission of the account holder; and
- Do not solicit or demand payment in exchange for disclosing a vulnerability or refraining from public disclosure.
If your research surfaces data you were not authorized to access, including personally identifiable information (PII), bank account data, credentials, or proprietary information belonging to CNote or its users:
- Stop testing immediately and submit a report right away;
- Limit the data you access or view to the minimum necessary to demonstrate the vulnerability;
- Do not download, copy, retain, or further distribute any such data, a screenshot of a small number of records (no more than 3–5) is sufficient to demonstrate a proof of concept; and
- If you inadvertently access, download, or retain any such data, delete it promptly, make no further use of it, and confirm the deletion in your report to us.
Safe Harbor
If you, in our sole determination, make a good faith effort to research and disclose vulnerabilities in accordance with this Policy, we will not pursue any legal action because of your research or responsible disclosure, subject to CNote’s compliance with applicable laws and legal obligations. To qualify for Safe Harbor, disclosures to us must be unconditional and may not involve extortion or threats.
For purposes of this Policy, “good faith security research” means accessing a computer solely for the purpose of good faith testing, investigation, and/or correction of a security flaw or vulnerability, in a manner designed to avoid harm to individuals or the public, where the information derived is used primarily to promote the security of the affected systems or the people who use them.
This Safe Harbor extends only to conduct that falls within the scope of this Policy. Conduct that falls outside this Policy’s scope, or that otherwise violates applicable law, is not authorized, and CNote reserves all rights and remedies with respect to such conduct.
If at any time you have concerns, or are uncertain whether your security research is consistent with this Policy, please contact us at security@mycnote.com before proceeding further. We will not pursue action against researchers who contact us in good faith to clarify scope or permitted activity before testing.
Eligibility
This Safe Harbor is not available to, and CNote reserves all rights and remedies against, any individual or entity that: is listed on the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) Specially Designated Nationals and Blocked Persons List or any other applicable U.S. sanctions list; is located in, or organized under the laws of, a jurisdiction subject to comprehensive U.S. sanctions; or is not otherwise in compliance with all applicable federal, state, and local law in connection with the research.
Disclosure Policy
Given the sensitivity of our data and our commitment to protecting our customers’ privacy, we ask that you avoid disclosing the existence of, or any details relating to, a suspected vulnerability to any third party or the public until you have received written confirmation from us that disclosure is appropriate. We will provide that confirmation once:
- The vulnerability has been fully remediated;
- CNote has reviewed and approved the disclosure details; and
- No sensitive information is included in the disclosure.
We fully support your right to publicly disclose a vulnerability you discover. Given the nature of the data CNote handles and our current scale, we ask only to coordinate with you on timing, so that we can protect our customers and the public, and complete remediation before details become public. If remediation is taking longer than you’d expect and you’d like a status update, contact us at security@mycnote.com and we’ll let you know where things stand.
Changes to This Policy
We may update this Policy from time to time. The version of this Policy in effect at the time you submit a report governs our handling of that report.
PGP Key
-----BEGIN PGP PUBLIC KEY BLOCK-----
xsFNBF5C6esBEACi1LCv1v4tvAEmJTLFmCu46lo/8gEp0EatqU6uMr7olNug
UiYuDtk3zehiMKjcwB2HQ6yXzVoe044THgB5ODl6Nw5+JLPEKRndEpB0ljtv
ATvV9m/gPDwjln8r/MtZYKZ6S+7bGDDIno/Y8BlPM6+X4T0D8jo5/fBtPvVk
bCq3TkGoZvrcmmPZ661me4y0Bmng9UGHseYiKTVAOPdxzOc1fQixAX+T8Kcg
wzvzeoWTVgsCEUEqcqJNdwCXWDweII3SRRubL5nDpInNhHkbICkrJyam6Hqe
IpxdYkZFymwWSJqXPhy3tfg4KL2teHXaTWxDpZQWGVrpc5PdwKTINX6OEWZ7
9YoGrPJlGc19Wxwm+35EJFRuDbDyXsbC89nLmq50si3JxONUmlhlS39DHWYT
/qPX2uX9IIFo3RK5zP+FJLu3Wf/42l0CSce4NkaTxpPaUW1e2eaNZ1nnkngN
uhSusmCQzd/qBwQQXt2z7Uvy8ABEZ3loVL0H4SW4SgUl09JAar0ASuwOeZa4
gwvPpnRErxHCUcUkouFHscxS6hxIZ0TrEkfA25XP1ZFAlEMkQLHxZmQQq7QN
NrI3q+I2jm9owG+YpO4VY/fAC7nbKcXW5g+9MIsUrIkWI4qQrhC5QaDbp4zE
Kk3KlrY3VDMTJp45Cggf/x9UQU4HhixdvqJxvwARAQABzSVjbm90ZS1zZWN1
cml0eSA8c2VjdXJpdHlAbXljbm90ZS5jb20+wsF1BBABCAAfBQJeQunrBgsJ
BwgDAgQVCAoCAxYCAQIZAQIbAwIeAQAKCRC9nJuMn4+Rc5q9D/4+mm6EZaP0
3RjeyBkINxd4hCMyRmuMReMsgRsbEZmCd1YTrays/EbCWxAlZb+SJPyHuw/Z
NogoKnMGjRFlUnWGYaKjHDAU1grC5LlacgBjEyMf7jn5sCapL1HCxnhroAST
QqBpjezGT/kUCqcjT4zt1uedeJzzsplTUfZIR1dgxJiRmBrAhqlG3lOxKG9S
VqInQPJJM6MptY6wgHYviLwoeF97msY4V8y9b4hqZg4uBrANXCjNyDn5reIx
PNxpP0gKaKaNbMgh7+oJnQfZUuYX4ITrEirt2jAxf0huHGuEU5fhcKGNlfVM
eizbni/ll4fr8csThpxh8GB8/2lk2LdUwoPUnVyP+URkvUixSZcatfmf6ki6
plqcpwk/jzfBPv3EMQ0EXO5vM827tCRkOIcpb3n5Zy9sD/5XW6zXPFhbeEA1
B/zmWo/FGCyNU2obwM9Tpuh4DxCyCmgLjgGUDGvoHtdwt1LO3U31N7pQY3yp
GlUGvFSMq/UkcCNAFKCzyAr9gL1STLXkPCbPXOioUfPYaSJDftxrqqQexNUS
xF1FGmhfP3lsxLMaNk2aryoP4TGflBr0J/GBBxpKt/7WWR4LT1eMTKPK9oLB
/jFrsl8me/hHh6jxz/fqNNaH5pydDvnMEtS37ul5se/7ccmJEnjXNHHv8QX/
AcnqvhX3Ofn4Pc7BTQReQunrARAA2hSw7FAiqxSwhqvmg6/ol+B6SIzPIxTE
1QE6I3f+vp7R9tSMQaZq0GVV53i08zH/xmf/r/qqNTbP/+tJ1LpJagO/PvL8
XX/VkeyFobzMWHbJ6TSNxCn5AhPcO4LXnWke8qIDalHwYCySnFNEJAO2egPV
JGgvL1O7ao1CoXLYUlGRasHTwFy57xJBOrdVH//hJtaQpUX6+f0tbvmfeLwH
YH4Q2+jhzNmuLlpPHf3Acn/zfSgYxA2FdYYgiiLsW+f2kPfMeoy8uddbAqP/
1S7CR8lCj1L3NuF/3GvmgORe3aNUgtqVMW2cAD5yG+YGcnlo1BH0hxFvTLYo
qKyT11IfPGcsNptp8TiE/0wa3E2VxE2VFcDUmW48FQD+FvI6QdVeRfGsD7/j
zsPMOHMLmjOj7J9a+h4zpdIrzGkwgbLihoXLALGZ1r5cJJm3JFjTBarlAiec
fMfjcQ16LKsITZlxeUwlW92cSmdT85CdcQlo/uvZivjpM1xQqdWVau6eiwOt
PJA0dZk56+Qr1vRNy89O0SHxSat+Oi3Z1/YIVj4D41tYgTf95wrMvHsxUYgg
5VvK7L9s0PdEJbZX+X15hPehn5dYNypjGDCGfXvP6AS6p2Nrtc3v19kD6XA4
is7D77fFI2X8E6Pn24ntWHtxE2RtXv62LfC6aJOQBCybOnuUYa8AEQEAAcLB
XwQYAQgACQUCXkLp6wIbDAAKCRC9nJuMn4+Rc7ucD/9LLF1DelJ73EGVt9uy
vytgxGEhJzRztjXQYEws80+jTjru4jqHkvYY/sQaHWgvFokoaKVaJ9c90DMg
EjQmmWa/aKnjTnyJDl3XLC76enm/XWOOWbuw1ndsjozVYO/kgQJ5NLzaUPc4
nku6tp2ESsspHw0tVKped0McHQLUY8qTR2BzuL6pYzfp4SIKlLVcK/PtF8Tt
wcD1k7w1KkiVI71aOQjj/smK4kzqt70t6SWep4AnIgs0GlhUv2cPQDUesjJd
kcIyV8GE0Rvjm7vmPuNL3wp6YGu2nyOV/gSjcx1E9sMjiDkyLivzQIRSJImY
rFe+gW58eysZjfp/IJNjturHR8j6ZCsVjJ88Q8v5i91+e6nC8xnYVZLN1cAo
64iEpkQCy8FITE4wl+/youO3OmomK+efqP1L74cAkMkBJs7SPOfaw7h1laDj
0VSPBdzmnTKNrSUwkia98KrtnziwBXixY6SG81pb78eQRoRPrRNpmNZSQiKN
B0mnECmeIZkYrt2BhayeJkMNskNbbGjoAJBJOMlcMt8cJKTt2DUadVK+KoVu
xEi89Mq7RQPnZvmLoR+dOB3QoiMAgGzshZDn9ArjKD9zHsWVX8EoXNcP8wUl
EBpN2DvynacVj8Uuu5FlqTYLEhGdFx9Aef2Xb1VGCDm+s3+O2cxDe98QDW8Y
lGO/eA==
=1SoT
-----END PGP PUBLIC KEY BLOCK-----

Recognition
Status: Remediated and Closed
Issue Summary: CNote received a vulnerability disclosure report regarding an exposed internal data orchestration service. Following remediation, CNote conducted a thorough internal investigation and engaged an independent cybersecurity forensic investigation firm. Both investigations found no evidence that customer data was accessed or exfiltrated.
Remediation Date: March 31, 2026
Severity Level: Priority
Acknowledgement: CNote would like to acknowledge qw3rjo for their assistance.
