Responsible Research & Safe Harbor

RESPONSIBLE VULNERABILITY
DISCLOSURE PROGRAM.

We welcome independent security researchers, reverse engineers, and developers to audit our platform. We commit to transparent coordination, timely patches, and legal safe harbor.

Scope of Research

The following targets are strictly in scope for security evaluations:

  • Kernel Security: Yama LSM bypasses, privilege escalation, or heap overflows in kernel/oneplus/msm8996.
  • Hardware Controls: Bypasses of USB Restricted Mode on locked devices (deny_new_usb).
  • Update Pipeline: Package signature spoofing, certificate validation bugs in otacerts.zip or CYRONIX Recovery.
  • Firewall Subsystem: Netfilter UID leakages or per-app traffic bypasses.
  • Platform Infrastructure: Vulnerabilities in cyronixos.cyronixsecurity.com or OTA distribution endpoints.

Out of Scope

To ensure ethical research, the following activities are strictly prohibited:

  • Distributed Denial of Service (DDoS) against download or OTA servers.
  • Social engineering or phishing targeting project maintainers.
  • Attacking upstream Tailscale mesh infrastructure.
  • Flaws requiring prior physical hardware modification or JTAG access.
  • Disclosing vulnerabilities publicly prior to our mutual disclosure window.

Reporting Process & PGP Contact

To submit a security advisory or report a flaw, email our engineering security desk. Please encrypt sensitive technical proofs of concept using our security PGP key:

Official Security Channel
Contact: security@cyronixsecurity.com
PGP Key ID: 0x4D2A90F18B33E629
Fingerprint: 8E12 79B3 0A94 C891 423D B499 4D2A 90F1 8B33 E629
Encrypted Triage: Submissions acknowledged within 48 business hours

Safe Harbor Guarantee

If you conduct vulnerability research in accordance with this policy, Cyronix Dev & Security considers your activity authorized under computer crime and anti-circumvention statutes. We will not pursue legal action against researchers acting in good faith.