Responsible Disclosure
As a dedicated cybersecurity firm, Nexus believes in maintaining the integrity of the global digital ecosystem. If you believe you have discovered a security flaw or operational vulnerability in our web assets or infrastructure, we welcome your report under this policy.
Last updated July 31, 2026Our Commitments
If you act in good faith and comply with this policy during your investigation, Nexus promises to:
- Acknowledge receipt of your vulnerability report within 24 hours of submission.
- Coordinate transparently with you to understand, isolate, and validate the technical exploit vectors.
- Abstain from initiating legal action or requesting law-enforcement reviews regarding your research activities.
Guidelines for Researchers
To ensure safe harbor and protect our active corporate systems, researchers must strictly adhere to the following guardrails:
- Avoid actions that cause persistent denial of service (DoS/DDoS), data destruction, or operational service degradation for Nexus users.
- Do not attempt to access, extract, modify, or compromise real client data, source-code files, or administrative configurations.
- Maintain complete confidentiality regarding the bug details. Do not publicly disclose the vulnerability before Nexus has officially patched and resolved the vector.
Ineligible Bug Classes
The following categories are currently out of scope for rewards or formal recognition unless they demonstrate a direct, high-impact exploit chain:
- Missing security headers or banner disclosures that do not lead to direct data exposure.
- SPF, DKIM, or DMARC configurations on staging or lookalike domains.
- Rate-limiting flaws on non-transactional contact portals.
How to Submit
Compile your technical proof of concept (PoC), step-by-step reproduction steps, and impact assessment into a secure file. Send it directly to our engineering response command center or contact our CEO, Tanvir Ahmed.
Submit a security reportsecurity@nexuswebsecurity.comNexus Web Security · Legal & Compliance
