Security & vulnerability disclosure

If you believe you have found a security issue in cdn22.net, please tell us privately so we can investigate and fix it.

How to report

Email np@cdn22.net with enough detail for us to reproduce the issue:

  • The affected URL, endpoint, or feature.
  • Step-by-step reproduction instructions.
  • What you expected to happen and what actually happened.
  • The impact you think the issue has, and when you observed it (with timezone).

Machine-readable contact details are published at /.well-known/security.txt.

Do not send sensitive data

Do not include customer data, other people's files, passwords, API keys, access tokens, or other secrets in your report. If a finding exposes such data, describe where and how it is exposed instead of copying it, and stop accessing it.

Testing scope

We welcome reports about issues you notice through normal, non-intrusive use of our public website, public links, and your own account. This page does not authorize intrusive testing. In particular, do not:

  • Access, modify, or delete data or files that do not belong to you.
  • Run denial-of-service, load, or automated high-volume scanning against our services.
  • Use social engineering, phishing, or physical attacks.
  • Attempt to pivot into or persist in our infrastructure.

What to expect

We review reports and will reply when we have questions or an update. cdn22.net does not run a bug bounty program and does not offer payment or rewards for reports.