1. How to report
Email suspected vulnerabilities to security@canopusbank.com. Include the affected URL or component, a clear description, reproducible steps, observed impact and any safe evidence available.
Do not include unnecessary personal data, credentials, private keys or data obtained from other users.
2. Scope
This policy currently covers the public website at www.canopusbank.com and first-party assets served from that domain. It does not authorise testing of third-party providers, email infrastructure, regulators, advisers or unrelated systems.
3. Good-faith testing rules
Please:
- avoid accessing, changing, deleting or exfiltrating data that is not your own;
- stop testing and report promptly if sensitive data becomes visible;
- avoid denial-of-service, traffic flooding, spam, social engineering, physical intrusion or malware;
- use the minimum testing necessary to demonstrate the issue;
- do not publicly disclose an unresolved vulnerability before a reasonable remediation period and coordinated discussion;
- comply with applicable law.
4. What you can expect
We aim to acknowledge credible reports, assess severity, request clarification where necessary and communicate a remediation path. Response times may vary because the project is pre-launch and not operated as a live bank.
5. Good-faith assurance
Where you comply with this policy and applicable law, we do not intend to pursue action solely for the authorised security research described here. This statement is not a waiver by third parties and cannot authorise conduct that the law prohibits.
6. Rewards and recognition
No bug-bounty payment or reward is promised. Any acknowledgement is discretionary and subject to legal, confidentiality and security considerations.
7. Fraud, impersonation and urgent concerns
Report suspected impersonation, fraudulent payment requests or misuse of the Canopus name to the same security address. Do not send funds or credentials in response to unsolicited communications.