Vulnerability Disclosure Policy

Last updated July 9, 2026

C2Stream is a product of C Squared Intelligence Technologies (“C2Stream,” “we,” “us”). Security is core to what we do, and we value the work of independent security researchers. This policy explains how to report a security vulnerability, what you can expect from us, and the conditions under which we authorize good-faith security research. A downloadable copy is available on request at support@c2stream.com.

How to report

Email support@c2stream.com with:

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions to reproduce it, including any URLs, requests, payloads, or accounts used.
  • Proof-of-concept material (screenshots, request/response captures, or a short video) — please redact any real personal data you may have encountered.
  • Your name or handle if you would like to be credited, and how to contact you.

Please do not include real personal data, client information, or live credentials in your report. If you encountered such data during testing, tell us it exists and delete your copy — do not send it to us. We accept reports in English; request our PGP key at the address above if you wish to encrypt your report.

Scope

In scope: the C2Stream web application at www.c2stream.com (and subdomains we operate) and its APIs.

Out of scope (report these to the relevant vendor under their own programs):

  • Services operated by our sub-processors (e.g., Google/Gmail, Anthropic, Supabase, Vercel, Stripe, Resend).
  • Findings requiring physical access to a device, or that depend on a compromised endpoint or pre-existing malware.
  • Social engineering, phishing, or pretexting against our staff, customers, or vendors.
  • Denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion attacks, and any testing that intentionally degrades the service.
  • Automated-scanner output submitted without a demonstrated, reproducible impact.

We generally triage the following as informational unless you can demonstrate real impact: missing best-practice HTTP headers, clickjacking on pages with no sensitive action, self-XSS, missing rate limiting without a working account-takeover or data-exposure path, issues affecting only end-of-life browsers, and raw TLS/SSL scanner output. If you can show genuine impact in any of these, we still want to hear it.

Our commitments to you

  • Acknowledge your report within five (5) business days.
  • Provide an initial assessment within ten (10) business days of acknowledgement.
  • Keep you reasonably informed of remediation progress.
  • Credit you publicly once the issue is resolved, if you wish (you may stay anonymous).
  • Not pursue or support legal action against you for good-faith research conducted under this policy (see Safe harbor).

Guidelines for researchers

  • Only test against accounts and data that belong to you. Create your own test account; do not access, modify, or delete another user’s or organization’s data.
  • Stop and report to us immediately if you encounter any personal data, privileged client information, or another user’s data — do not access, copy, store, transfer, or disclose it.
  • Do not perform actions that could harm the reliability or integrity of the service (including DoS/DDoS, spam, or automated high-volume testing).
  • Do not use social engineering, phishing, or physical intrusion.
  • Give us a reasonable period to remediate before disclosing publicly, and coordinate the timing of any disclosure with us.
  • Do not demand payment, threaten to publish, or otherwise attempt to extort us in exchange for withholding a vulnerability — this falls outside good-faith research.
  • Comply with all applicable laws.

Safe harbor

We consider security research and vulnerability disclosure conducted in good faith and in accordance with this policy to be authorized conduct. If you make a good-faith effort to comply with this policy, we will consider your research authorized access for purposes of applicable anti-hacking laws (including the U.S. Computer Fraud and Abuse Act) and applicable anti-circumvention laws (including the DMCA); we will not bring or support a claim against you under those laws or under our terms of service for your research; and we will waive any relevant restriction in our terms of service to the limited extent necessary to perform it.

This safe harbor applies only to legal claims within our control. It does not bind, and cannot waive claims by, any third party — including our sub-processors, other customers, or government authorities. You are expected to comply with applicable law and to act in good faith at all times. This policy does not authorize activity that intentionally accesses, damages, or exfiltrates data beyond what is necessary to demonstrate a vulnerability. If in doubt whether specific conduct is authorized, ask us first at support@c2stream.com before proceeding.

Coordinated disclosure

We support coordinated disclosure. Please keep vulnerability details confidential until we have had a reasonable opportunity to remediate, and coordinate any public disclosure with us. Absent a specific written agreement, we ask for up to 90 days from your report before public disclosure, and we will make reasonable efforts to remediate high-severity issues sooner.

Rewards

We do not currently operate a paid bug-bounty program and do not offer monetary rewards. We recognize valid reports with our thanks and, if you wish, public credit. This may change in the future.

Contact

Security reports and questions: support@c2stream.com. This policy is governed by the laws of the United States and the state in which C Squared Intelligence Technologies is organized. We may update this policy; the version in effect at the time of your research governs it.