SECURITY POLICY · COORDINATED DISCLOSURE

Report security weaknesses safely and with enough evidence to act.

This policy defines the public web scope, safe research boundaries, report content, acknowledgement and remediation process, and excluded activity.

Owner
Security Assurance
Version
1.3
Effective
05 Aug 2026
Language
English

1. In-scope surface

The canonical HTTPS site, public documentation, authentication gateway, authenticated console, Control API routes, public status endpoints, and published security headers are in scope when tested with an identity and data you are authorized to use.

Regional provider infrastructure, third-party services, DNS providers, hosting control panels, gateway protocols, and networks or identities not owned by the reporter are outside this policy unless written authorization explicitly includes them.

2. Safe research expectations

  • Use the minimum requests needed to demonstrate the condition.
  • Stop when unauthorized data access, control, or material service impact is proven.
  • Do not retain personal data, credentials, cookies, private keys, or non-public tenant material.
  • Do not use social engineering, credential stuffing, malware, persistence, destructive mutation, traffic flooding, or denial-of-service methods.
  • Do not publish an unremediated exploit or secret.
Good-faith handling

Research that stays within this policy, avoids harm, and is reported promptly will be treated as good-faith security research. This statement does not authorize activity prohibited by applicable law or by systems outside NBS control.

3. What to include

FieldUseful detail
Affected surfaceExact host, route, method, and component
ConditionsIdentity role, browser or client, and required state
ReproductionMinimal ordered steps with sensitive values removed
ImpactWhat unauthorized action or disclosure becomes possible
EvidenceUTC time, response status, request ID, and redacted output
ContactA safe method for clarification and coordinated disclosure

4. Report channel and response

Start from the contact and policy locations published at /.well-known/security.txt. Reports are acknowledged within three business days. Triage validates scope, reproducibility, severity, and existing controls. Confirmed critical issues enter immediate containment review; other findings are assigned an owner and remediation target based on risk.

5. Coordination and closure

Status is shared at validation, material remediation milestones, and closure when a return channel is available. A report is closed with the affected version, remediation summary, validation result, and disclosure decision. Public acknowledgement is optional and requires mutual agreement.