1. What to report
- vulnerabilities enabling unauthorised access, code execution or session takeover;
- bypasses of authentication, authorisation, user consent or tenant isolation;
- exposure of passwords, tokens, keys, personal data or session data;
- integrity issues affecting updates, installers, images or checksums;
- serious defects that may delete data or reduce system security.
2. Information to include
Include the product and version, operating system, prerequisites, exact reproduction steps, impact, a safe proof of concept and suggested mitigation. Remove third-party data and provide only what is necessary for analysis.
3. Responsible testing
- test your own instances, accounts and devices or obtain the owner’s explicit permission;
- do not use social engineering, phishing, DoS/DDoS, persistence or destructive tests;
- do not download, alter or disclose data beyond the minimum needed to demonstrate the issue;
- stop when testing may affect other users, production or data integrity;
- allow N3X a reasonable time to investigate and remediate before disclosure.
4. Report handling and coordination
Reports are prioritised by impact and exploitability. N3X aims to acknowledge receipt, reproduce safely, contain impact, prepare a fix and provide material updates. Free products have no guaranteed SLA or bounty programme unless separately announced.
The public-disclosure date will be coordinated according to risk, fix availability and legal duties. N3X will not request secrecy longer than necessary to protect users, and the reporter should withhold details that enable exploitation.
5. Updates and supported versions
A fix is usually released in the latest version of a supported product line and may require an upgrade rather than a backport. Security updates for products within a statutory support period remain free and available for the required period. See the Support and Lifecycle Policy.
6. Urgent incident
If a vulnerability is actively exploited or creates an immediate risk to data or remote access, use “URGENT / ACTIVE EXPLOIT” in the subject and include time, product, version, indicators, possible impact and containment already taken. Do not send passwords, private keys or unnecessary personal data.
7. Incidents and regulatory duties
N3X assesses and documents incidents and, where legally required, reports an actively exploited vulnerability, severe incident or personal-data breach to the competent authority and informs affected users. A user need not report a product vulnerability on N3X's behalf, but should provide information promptly and preserve evidence.
The operator of a self-hosted N3XRemote, N3XMarket or N3X Remiza instance remains independently responsible for incidents and personal-data breaches in its infrastructure. N3X may help determine whether the cause lies in the product, configuration or environment, but does not become that instance's controller.
