Home Security, Privacy & Trust Responsible Vulnerability Disclosure

Responsible Vulnerability Disclosure

Last updated on Jun 06, 2026

TL;DR

๐Ÿ›ก๏ธ We welcome good-faith security research. Report via security@nexcyber.eu (PGP key below). Safe harbor for in-scope, in-policy research.


๐Ÿ“ฅ How to report

  • โœ‰๏ธ Email: security@nexcyber.eu
  • ๐Ÿ”‘ PGP fingerprint: published at https://nexcyber.eu/.well-known/security.txt (RFC 9116)
  • ๐Ÿ“‹ Include: affected component, vulnerability type, reproduction steps, impact, your contact

โœ… In scope

  • nexcyber.eu (the live app)
  • api.nexcyber.eu (backend API)
  • support.nexcyber.eu, docs.nexcyber.eu (support stack)

๐Ÿšซ Out of scope

  • nexcyber.eu (parking page โ€” not the live app)
  • DoS / volumetric attacks
  • Social engineering of our team
  • Vulnerabilities requiring physical access

โš–๏ธ Safe harbor

Good-faith research, within scope, without data exfiltration โ†’ no legal action. Please don't test on production without authorization.

โฑ๏ธ Our commitments

  • ๐Ÿ“ฉ Acknowledgment: within 24 hours
  • ๐Ÿ” Triage: within 3 business days
  • ๐Ÿ” Regular updates until resolution
  • ๐Ÿ† Optional Hall of Fame credit

โžก๏ธ Next


๐Ÿ’ฌ Need help?

Reach out via our live chat (bottom-right) โ€” Captain AI replies instantly, human experts within business hours. Email support@nexcyber.eu with [P1] for Command/Strategic priority issues.

โ„น๏ธ Disclaimer โ€” NexCyber provides a readiness analysis, not legal advice. Final compliance may require legal review or notified body certification.

Last reviewed: 2026-06-02 ยท NexCyber Help Center