CyberShield Security Policy & Vulnerability Disclosure

Effective Date: December 4, 2025

At CyberShield Technology Solutions, keeping our customers’ data secure is our highest priority. We welcome the contribution of external security researchers and look forward to working with the research community to keep our systems and our clients safe.

Vulnerability Disclosure Policy

If you believe you have found a security vulnerability in one of our products, services, or web applications, we encourage you to let us know as soon as possible. We will work with you to resolve the issue promptly.

Safe Harbor

We consider security research and vulnerability disclosure activities conducted consistent with this policy to be “authorized” conduct. We will not pursue legal action against you or initiate a law enforcement investigation if you:

  • Test only systems that are within the scope defined below.

  • Do not compromise the privacy or safety of our clients, employees, or third parties.

  • Do not destroy data or interrupt our services (e.g., DoS/DDoS attacks are strictly prohibited).

  • Comply with all applicable laws.

If you are conducting research in good faith and in accordance with this policy, we will consider your activities authorized.

Scope

The following systems and services are in scope for testing:

  • The following domain names and their subdomains:
    • crossroadscomputer.com
    • cybershieldms.com
    • cybershieldms.net
    • cybershieldts.com
    • cybershieldtechsol.com
    • cybershield-usa.com
    • cybershield.it.com
    • cybershieldvoip.com
    • cybershieldvoice.com
    • cybershieldts.net
    • cybershieldprotect.net
    • cybershieldtechnology.com
    • cybershieldtechsol.net

Out of Scope:

  • Third-party services hosted by vendors (e.g., Microsoft 365, Google Workspace) — please report issues directly to those vendors.

  • Social Engineering (phishing) of our employees or customers.

  • Physical security attacks against our offices, data centers, or home offices.

How to Report a Vulnerability

Please submit your report via email to [email protected] .

What to include in your report:

  1. Description: The nature of the vulnerability.

  2. Location: The URL or IP address where the issue exists.

  3. Proof of Concept: Steps to reproduce the issue (screenshots or video are helpful).

  4. Impact: How the vulnerability could be exploited.

Our Commitment to You

When you choose to share your findings with us, we commit to the following:

  • Acknowledgement: We will acknowledge receipt of your report within 3 business days.

  • Review: We will confirm the existence of the vulnerability and keep you informed of our progress.

  • Remediation: We will fix validated vulnerabilities in a timely manner.

  • Recognition: With your permission, we may recognize your contribution in our “Security Hall of Fame” (coming soon).


General Security Measures (For Clients)

Beyond our disclosure program, CyberShield employs a defense-in-depth strategy to protect our managed clients, aligned with NIST 800-171 and CMMC standards.

  • 24/7 Monitoring: We utilize continuous threat detection and response managed by our Security Operations Center (SOC).

  • Compliance: Our internal policies comply with HIPAA and relevant federal contractor requirements.

  • Encryption: All sensitive data is encrypted in transit and at rest.

  • Access Control: We utilize strict Multi-Factor Authentication (MFA) and Least Privilege principles for all internal and client access.