SECURITY POLICY · COORDINATED DISCLOSURE
Report security weaknesses safely and with enough evidence to act.
This policy defines the public web scope, safe research boundaries, report content, acknowledgement and remediation process, and excluded activity.
1. In-scope surface
The canonical HTTPS site, public documentation, authentication gateway, authenticated console, Control API routes, public status endpoints, and published security headers are in scope when tested with an identity and data you are authorized to use.
Regional provider infrastructure, third-party services, DNS providers, hosting control panels, gateway protocols, and networks or identities not owned by the reporter are outside this policy unless written authorization explicitly includes them.
2. Safe research expectations
- Use the minimum requests needed to demonstrate the condition.
- Stop when unauthorized data access, control, or material service impact is proven.
- Do not retain personal data, credentials, cookies, private keys, or non-public tenant material.
- Do not use social engineering, credential stuffing, malware, persistence, destructive mutation, traffic flooding, or denial-of-service methods.
- Do not publish an unremediated exploit or secret.
Research that stays within this policy, avoids harm, and is reported promptly will be treated as good-faith security research. This statement does not authorize activity prohibited by applicable law or by systems outside NBS control.
3. What to include
| Field | Useful detail |
|---|---|
| Affected surface | Exact host, route, method, and component |
| Conditions | Identity role, browser or client, and required state |
| Reproduction | Minimal ordered steps with sensitive values removed |
| Impact | What unauthorized action or disclosure becomes possible |
| Evidence | UTC time, response status, request ID, and redacted output |
| Contact | A safe method for clarification and coordinated disclosure |
4. Report channel and response
Start from the contact and policy locations published at /.well-known/security.txt. Reports are acknowledged within three business days. Triage validates scope, reproducibility, severity, and existing controls. Confirmed critical issues enter immediate containment review; other findings are assigned an owner and remediation target based on risk.
5. Coordination and closure
Status is shared at validation, material remediation milestones, and closure when a return channel is available. A report is closed with the affected version, remediation summary, validation result, and disclosure decision. Public acknowledgement is optional and requires mutual agreement.
Operational