Vulnerability Disclosure Policy
- Last updated
- August 16, 2026
- Effective date
- June 29, 2026
- Sections
- 10
NUEXUS Technologies (Private) Limited ("NUEXUS") welcomes reports of security vulnerabilities in the systems we operate. We test other people's systems for a living, so we know what it is like to find something and have nowhere to send it. This page is the somewhere.
A machine-readable version of this policy is published at /.well-known/security.txt, following RFC 9116.
1. Purpose
To give security researchers a clear, safe and predictable way to report a vulnerability to us, and to set out what we will do when they do.
2. Scope
This policy covers internet-facing systems that NUEXUS owns and operates, including:
- This website and its subdomains.
- Web applications and APIs published by NUEXUS under a NUEXUS domain.
- Products NUEXUS builds and hosts itself.
If you are not sure whether something is in scope, ask before you test. We would much rather answer that question than have you guess.
3. Out of Scope
The following are not covered, and should not be tested:
- Systems NUEXUS operates for a customer but does not own. We deliver managed services, so some infrastructure we touch belongs to someone else. We cannot authorise testing of it, and neither can you assume it. See section 9.
- Third-party services we merely use, such as a hosting provider or a payment processor. Report those to their own programmes.
- Denial of service, volumetric testing, resource exhaustion, and anything else whose method is to degrade availability.
- Social engineering, phishing, or physical attempts against our staff, offices or suppliers.
- Reports produced solely by running an automated scanner, with no demonstrated impact. A raw tool output is not a finding.
- Missing hardening headers, weak TLS ciphers, or similar configuration observations with no demonstrable exploit path. We are happy to receive these, but we will treat them as advice rather than vulnerabilities.
4. How to Report
Email security@nuexus.com with "Security" in the subject line. A useful report includes:
- The affected URL, endpoint or component.
- A description of the issue and why it matters.
- Clear steps to reproduce it, so we can confirm it without guessing.
- Any proof-of-concept material, and the accounts or data you touched.
- How you would like to be credited, if you would like to be.
Please report in English, and please send one issue per email so each one can be tracked separately.
5. What We Will Do
- Acknowledge your report. This is the one thing we commit to unconditionally.
- Investigate it and tell you whether we have reproduced it.
- Keep you informed while we work on a fix, and tell you when it ships.
- Credit you publicly if you want that, or keep you anonymous if you prefer.
- Tell you plainly if we decide not to fix something, and why.
We aim to respond quickly, and in practice usually do. We deliberately do not publish a fixed response-time guarantee here, because we are a small team and a number we cannot always honour would be worth less to you than this sentence.
6. What We Ask of You
- Give us reasonable time to investigate and fix an issue before disclosing it publicly.
- Use only the minimum access needed to demonstrate the problem. Stop as soon as you have proved it, and do not pivot further into the system.
- Do not access, modify, delete or store other people's data. If you encounter personal data, stop immediately and tell us what you saw so we can assess it.
- Do not degrade or interrupt our services, and do not test with production data belonging to others.
- Use test accounts where you can, and tell us which accounts you used.
- Comply with the applicable law. Nothing here authorises anything unlawful.
7. Safe Harbour
If you follow this policy in good faith, NUEXUS will not initiate or support legal action against you in connection with your research, and we will treat your work as authorised for the purposes of our own acceptable-use terms.
To be honest about the limits of that promise: it binds NUEXUS, and only NUEXUS. We cannot grant safe harbour on behalf of a hosting provider, a third-party service, a customer, or any authority. If your research would touch a system we do not own, section 9 applies instead.
8. Recognition, Not Payment
NUEXUS does not currently run a paid bug bounty, and we would rather say that here than let you spend time on the assumption that we do. What we offer is acknowledgement, credit where you want it, and a direct line to engineers who will actually read your report. If that changes, this page will say so.
9. Reporting an Issue in a Customer System
If you believe you have found a vulnerability in a system NUEXUS manages for a client, do not test it further. Email us with what you observed and how you came across it, and we will route it to the system owner. Only the owner can authorise testing of their own environment, which is the same rule our own engagements follow: we require written authorisation before any testing begins.
10. Contact
NUEXUS Technologies (Private) Limited
Email: security@nuexus.com (subject: Security)
Machine-readable: /.well-known/security.txt
Related: Terms and Conditions, Privacy Policy, Disclaimer.
