Responsible Disclosure
Found a security issue? Tell us.
We take security seriously. If you discover a vulnerability in NexusForgeBot, please report it responsibly. We commit to investigating all reports promptly and communicating with researchers in good faith.
How to report
Contact us via our Discord support server with a description of the vulnerability, steps to reproduce, and any relevant technical details. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and address it.
What to include
A clear description of the vulnerability, steps to reproduce, the potential impact, any proof-of-concept code (do not exploit live data), and your Discord username for follow-up.
Our commitments
We will acknowledge your report within 3 business days. We will investigate and provide updates on our progress. We will not pursue legal action against good-faith security researchers. We will credit researchers upon request when disclosing fixed vulnerabilities.
Scope
In scope: authentication, authorization, data access controls, session management, API security, NSN data handling. Out of scope: social engineering, physical attacks, third-party services not under our control, denial-of-service attacks.