Responsible Disclosure Policy
At Nexura Security, the safety of our users is our highest priority. If you believe you've found a security vulnerability in our plugin, website, or infrastructure, we encourage you to report it to us immediately.
How to Report a Vulnerability
Please send an email to [email protected] with the following details:
- Description of the vulnerability and its potential impact.
- Steps to reproduce the issue (including any proof-of-concept scripts).
- Your contact details so we can follow up.
PGP Key: If you are sending sensitive exploit data, please ask for our public PGP key before transmitting the details.
Our Commitment
When you responsibly disclose a vulnerability to us, we promise to:
- Acknowledge receipt of your report within 48 hours.
- Provide an estimated timeline for the fix.
- Notify you when the vulnerability has been patched.
- Publicly acknowledge your contribution in our changelog (if you desire).
Rules of Engagement
To ensure a safe and responsible disclosure process, we ask that you:
- Do not exploit the vulnerability to access, modify, or destroy user data.
- Do not perform any attacks that could degrade the performance of our services (e.g., DDoS).
- Give us reasonable time to resolve the issue before disclosing it publicly.
