Security & Vulnerability Disclosure
Last Updated: August 2, 2026
1. Foundational Security Architecture
The CyCity Quantum Web Standard (CQWS) is engineered on the absolute cutting edge of Information-Theoretic security. By strictly utilizing the Dilithium (NIST FIPS 204) and Kyber (NIST FIPS 203) cryptographic suites, our network infrastructure is theoretically immune to Shor's algorithm executed on sufficiently stable, large-scale quantum computers.
Unlike traditional TLS wrappers, CQWS operates deep within the kernel (Ring-0). We intercept packets prior to standard TCP/IP stack evaluation, injecting quantum-resistant entropy and verifying digital signatures in real-time, effectively creating a zero-trust cryptographic perimeter around your server.
2. Secure Software Development Lifecycle (SSDLC)
CyCity employs a rigorous SSDLC to ensure that vulnerabilities are not introduced during the engineering phase of the CQWS daemon and Billing API.
- Static and Dynamic Analysis: All code pushed to our repositories undergoes automated SAST and DAST scanning to detect memory leaks, buffer overflows, and unsafe cryptographic implementations.
- Peer Review & Red Teaming: No code enters production without multi-party peer review. Furthermore, CyCity retains independent, third-party cryptographic auditors to conduct routine penetration testing against our Dilithium signature bridge.
- Minimal Attack Surface: The CQWS daemon is compiled in a hardened environment and statically linked to minimize reliance on potentially vulnerable host-system libraries (e.g., glibc).
3. Responsible Vulnerability Disclosure
We consider the security of our systems a top priority. If you are a security researcher and have discovered a vulnerability in the CQWS daemon, the CyCity API, or the administrative dashboard, we strongly encourage you to disclose it to us responsibly.
Please submit a detailed report to security@cycity.space. To protect sensitive information during transit, we mandate that all vulnerability reports be encrypted using our public PGP key.
mQINBGBz... [Refer to cycity.space/.well-known/security.txt for full key]
-----END PGP PUBLIC KEY BLOCK-----
We request that you do not publicly disclose the vulnerability until we have had a reasonable timeframe (typically 90 days) to issue a comprehensive patch to all active enterprise nodes.
4. Safe Harbor and Bug Bounty Program
CyCity will not take legal action against security researchers who discover and report vulnerabilities in good faith and in accordance with this disclosure policy.
While CyCity does not currently operate a public cash bug bounty program, we do maintain a highly prestigious Security Hall of Fame. Researchers who provide actionable, critical intelligence regarding side-channel attacks on our Kyber/Dilithium implementations or remote code execution (RCE) vulnerabilities in our API will receive public acknowledgment, exclusive CyCity challenge coins, and complimentary enterprise licensing.