Last Updated: September 18, 2026
Our Commitment to Security
Security is core to our values, and we value the contributions of security researchers acting in good faith to help us maintain a high standard of security and privacy for our users, partners, and employees. This Vulnerability Disclosure Policy (“Policy”) describes how to report a suspected vulnerability to CNote Group, Inc. (“CNote,” “we,” or “us”), what we ask of researchers acting in good faith, and what you can expect from us in return, including the scope of our Safe Harbor protections.
This Policy is not a bug bounty program. CNote does not currently offer monetary rewards for reports submitted under this Policy.
Scope
This Policy covers systems CNote owns and operates. Scope is defined by domain and asset class rather than by hostname.
In Scope
- Any subdomain of mycnote.com or cnotegroup.com, in any environment, including production, staging, or demo, except as excluded below.
- CNote applications and CNote data wherever they run, including on third-party application platforms and at provider-assigned endpoints such as a CDN, load balancer, container platform, API gateway, or object store.
- CNote cloud storage where public access exposes data not intended to be public, or where unauthenticated write access is possible. Some CNote storage intentionally serves public website content; that alone is not a finding.
- Issues reachable without credentials, or with credentials for an account you own.
Out of Scope
- Systems CNote does not operate. Our public marketing website and blog are served by a managed hosting platform we do not run and cannot authorize testing of; the same applies to third-party services on their own domains. Report those to the vendor, and tell us if CNote data is involved. CNote’s own content, configuration, and code on those platforms remain in scope.
- Internal systems. Some CNote hostnames resolve to private, non-internet-routable addresses. Reaching internal networks by VPN, credential reuse, pivoting, SSRF, or any other route is outside this Policy.
- Denial of service, load testing, and resource exhaustion against any CNote system whether or not otherwise in scope.
- Social engineering, phishing, and physical access directed at CNote staff, customers, partners, or facilities.
- Findings that require a compromised device, a malicious browser extension, or a privileged network position.
- Reports with no demonstrated exploitable impact: raw scanner output; email authentication records without a working spoofing demonstration; missing rate limiting; self-XSS; clickjacking on pages carrying no sensitive action; cookie flags on non-session cookies; software version banners.
- Compromises that rely on insider access rather than an external technical vulnerability.
- Account takeover attempts, credential stuffing, or brute-force attacks against any account other than one you own.
- Reflected file download (RFD) findings.
- Dependency hijacking or typosquatting of CNote package or library names.
- Testing that intentionally alters, corrupts, or deletes data belonging to another user.
- Reports of a vulnerability in third-party software CNote uses where a vendor patch has been publicly available for fewer than 30 days, absent evidence of active exploitation.
If It Is Serious and Not Listed Here, Tell Us Anyway
This scope defines what we can authorize you to test. It is not a list of what we want to hear about. If you believe you have found a serious issue affecting CNote systems or CNote customer data, including on a system not named here, report it to us. We will treat it as a good faith disclosure.
How to Report a Vulnerability
Official Channel
Contact us via email at security@mycnote.com with a detailed report of the suspected vulnerability.
Your report should include as much of the following as possible:
- Type of vulnerability;
- Whether the information has been published, shared with others, or otherwise disclosed;
- Affected sites, systems, or configurations;
- Step-by-step instructions or proof-of-concept code sufficient to replicate the issue; and
- Your assessment of severity or impact, and a CVSS score or CWE classification if known (not required).
What You Can Expect From Us
When you submit a report consistent with this Policy, you can expect us to:
- Work in good faith to understand and validate your report;
- Work to remediate confirmed vulnerabilities in a timeframe appropriate to their severity, and communicate with you about our remediation timeline where appropriate;
- Extend Safe Harbor for security research conducted consistent with this Policy; and
- With your permission, attribute your name and contribution on any public disclosure we make, to the extent we choose to make a public disclosure.
Ground Rules
To encourage vulnerability research and to avoid any confusion between good faith research and malicious activity, we ask that you:
- Play by the rules, including this Policy and any other relevant agreements. If there is any inconsistency between this Policy and any other applicable terms, this Policy governs for activity conducted in accordance with it;
- Report any vulnerability you discover promptly, and avoid disclosing it to others until it has been resolved consistent with our Disclosure Policy below;
- Avoid violating the privacy of others, disrupting our systems or those of our users, destroying data, or degrading user experience;
- Use only the Official Channel described above to discuss vulnerability information with us;
- Perform testing only on in-scope systems, and respect systems and activities that are out of scope;
- Only interact with test accounts you own, or with the explicit permission of the account holder; and
- Do not solicit or demand payment in exchange for disclosing a vulnerability or refraining from public disclosure.
If your research surfaces data you were not authorized to access, including personally identifiable information (PII), bank account data, credentials, or proprietary information belonging to CNote or its users:
- Stop testing immediately and submit a report right away;
- Limit the data you access or view to the minimum necessary to demonstrate the vulnerability;
- Do not download, copy, retain, or further distribute any such data, a screenshot of a small number of records (no more than 3–5) is sufficient to demonstrate a proof of concept; and
- If you inadvertently access, download, or retain any such data, delete it promptly, make no further use of it, and confirm the deletion in your report to us.
Safe Harbor
If you, in our sole determination, make a good faith effort to research and disclose vulnerabilities in accordance with this Policy, we will not pursue any legal action because of your research or responsible disclosure, subject to CNote’s compliance with applicable laws and legal obligations. To qualify for Safe Harbor, disclosures to us must be unconditional and may not involve extortion or threats.
For purposes of this Policy, “good faith security research” means accessing a computer solely for the purpose of good faith testing, investigation, and/or correction of a security flaw or vulnerability, in a manner designed to avoid harm to individuals or the public, where the information derived is used primarily to promote the security of the affected systems or the people who use them.
This Safe Harbor extends only to conduct that falls within the scope of this Policy. Conduct that falls outside this Policy’s scope, or that otherwise violates applicable law, is not authorized, and CNote reserves all rights and remedies with respect to such conduct.
If at any time you have concerns, or are uncertain whether your security research is consistent with this Policy, please contact us at security@mycnote.com before proceeding further. We will not pursue action against researchers who contact us in good faith to clarify scope or permitted activity before testing.
Eligibility
This Safe Harbor is not available to, and CNote reserves all rights and remedies against, any individual or entity that: is listed on the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) Specially Designated Nationals and Blocked Persons List or any other applicable U.S. sanctions list; is located in, or organized under the laws of, a jurisdiction subject to comprehensive U.S. sanctions; or is not otherwise in compliance with all applicable federal, state, and local law in connection with the research.
Disclosure Policy
Given the sensitivity of our data and our commitment to protecting our customers’ privacy, we ask that you avoid disclosing the existence of, or any details relating to, a suspected vulnerability to any third party or the public until you have received written confirmation from us that disclosure is appropriate. We will provide that confirmation once:
- The vulnerability has been fully remediated;
- CNote has reviewed and approved the disclosure details; and
- No sensitive information is included in the disclosure.
We fully support your right to publicly disclose a vulnerability you discover. Given the nature of the data CNote handles and our current scale, we ask only to coordinate with you on timing, so that we can protect our customers and the public, and complete remediation before details become public. If remediation is taking longer than you’d expect and you’d like a status update, contact us at security@mycnote.com and we’ll let you know where things stand.
Changes to This Policy
We may update this Policy from time to time. The version of this Policy in effect at the time you submit a report governs our handling of that report.
