Vulnerability Disclosure Policy
How to report a security issue in Nubesti systems, our safe harbor, and what is out of scope.
Last updated: September 21, 2026
If you find a security issue in Nubesti systems (our website, portal, or platform—not a customer target), we want to hear from you. This is the policy referenced by /.well-known/security.txt.
Customer-target findings belong to that customer. Do not send us exploit details about a third party’s production systems.
1. How to report
Email [email protected] with:
- A clear description and impact
- Steps to reproduce
- Affected URL, endpoint, or component
- Proof that does not destroy data or expose other customers
We aim to acknowledge within 24 hours and give an initial assessment within 48 hours.
2. Safe harbor
We will not pursue civil or criminal action against researchers who:
- Act in good faith
- Avoid privacy violations, data destruction, and service degradation
- Do not access data that is not theirs beyond what is needed to demonstrate the issue
- Give us a reasonable chance to fix the issue before public disclosure
This safe harbor does not cover attacks on customer environments, physical intrusion, or extortion.
3. Out of scope
- Denial-of-service or volumetric floods against production
- Spam, social engineering of staff, or phishing our customers
- Physical attacks
- Findings that only affect outdated browsers or require MITM on the researcher’s own machine
- Issues in third-party products we do not operate, except for a clear misconfiguration we control
4. Coordination
Please do not post a full exploit before we have a fix or have agreed a disclosure date. We are happy to credit researchers who want to be named, unless they prefer to stay anonymous.
We do not currently run a public bug-bounty program. A thank-you or swag may be offered at our discretion; payment is not promised.