Responsible Vulnerability Disclosure
TL;DR
๐ก๏ธ We welcome good-faith security research. Report via security@nexcyber.eu (PGP key below). Safe harbor for in-scope,
in-policy research.
๐ฅ How to report
- โ๏ธ Email: security@nexcyber.eu
- ๐ PGP fingerprint: published at https://nexcyber.eu/.well-known/security.txt (RFC 9116)
- ๐ Include: affected component, vulnerability type, reproduction steps, impact, your contact
โ
In scope
- nexcyber.eu (the live app)
- api.nexcyber.eu (backend API)
- support.nexcyber.eu, docs.nexcyber.eu (support stack)
๐ซ Out of scope
- nexcyber.eu (parking page โ not the live app)
- DoS / volumetric attacks
- Social engineering of our team
- Vulnerabilities requiring physical access
โ๏ธ Safe harbor
Good-faith research, within scope, without data exfiltration โ no legal action. Please don't test on production without
authorization.
โฑ๏ธ Our commitments
- ๐ฉ Acknowledgment: within 24 hours
- ๐ Triage: within 3 business days
- ๐ Regular updates until resolution
- ๐ Optional Hall of Fame credit
โก๏ธ Next
- ๐ How we protect your data
- ๐ Sub-processors list
๐ฌ Need help?
Reach out via our live chat (bottom-right) โ Captain AI replies instantly, human experts within business hours. Email
support@nexcyber.eu with [P1] for Command/Strategic priority issues.
โน๏ธ Disclaimer โ NexCyber provides a readiness analysis, not legal advice. Final compliance may require legal review or
notified body certification.
Last reviewed: 2026-06-02 ยท NexCyber Help Center