[ LEGAL ]
Responsible Disclosure
v2026.05-draft · 2026-05-20
Scope
Good-faith security research against nnsec.com and published staging hosts listed in our scope file.
Out of scope
- Denial-of-service against production
- Social engineering of staff or customers
- Physical attacks
Reporting
Email [ciso_email] with reproduction steps, impact, and suggested remediation. Encrypt sensitive attachments on request.
Safe harbor
We will not pursue legal action for good-faith research that follows this policy and allows 90 days coordinated disclosure before public release.
Recognition
Eligible reports may receive acknowledgment in our security page hall of fame at our discretion.
Placeholders: ciso_email
Template text — counsel review before production. Questions: [email protected]