Vulnerability disclosure

CyberExchange accepts good-faith reports concerning vulnerabilities in NumTrade systems.

Confirmed findings may be eligible for a discretionary bounty, assessed from impact, report quality, and reproducibility. Submission does not guarantee compensation.

Public key

Download the CyberExchange public key to encrypt a report locally, then email it to cybercve@numtrade.in.

Fingerprint: 0688 17A4 3AC1 25E2 E5BB 27CD 5FBD 9140 5B06 F78D

Key expiry: 1 January 2030

Encrypted disclosure

Include the affected component, observed impact, and reproducible steps. A CVE ID is optional.

Encrypted locally before your email application is opened.