N3X
N3X Security

Security and vulnerability disclosure

How to safely report an issue affecting N3X applications, Docker images, updates or infrastructure.

Version 2.0 · updated:

Security contact: studio@n3x.pl (subject: [SECURITY]). Do not use a public issue or social media when a report contains details that could enable exploitation.

1. What to report

  • vulnerabilities enabling unauthorised access, code execution or session takeover;
  • bypasses of authentication, authorisation, user consent or tenant isolation;
  • exposure of passwords, tokens, keys, personal data or session data;
  • integrity issues affecting updates, installers, images or checksums;
  • serious defects that may delete data or reduce system security.

2. Information to include

Include the product and version, operating system, prerequisites, exact reproduction steps, impact, a safe proof of concept and suggested mitigation. Remove third-party data and provide only what is necessary for analysis.

3. Responsible testing

  • test your own instances, accounts and devices or obtain the owner’s explicit permission;
  • do not use social engineering, phishing, DoS/DDoS, persistence or destructive tests;
  • do not download, alter or disclose data beyond the minimum needed to demonstrate the issue;
  • stop when testing may affect other users, production or data integrity;
  • allow N3X a reasonable time to investigate and remediate before disclosure.

4. Report handling and coordination

Reports are prioritised by impact and exploitability. N3X aims to acknowledge receipt, reproduce safely, contain impact, prepare a fix and provide material updates. Free products have no guaranteed SLA or bounty programme unless separately announced.

The public-disclosure date will be coordinated according to risk, fix availability and legal duties. N3X will not request secrecy longer than necessary to protect users, and the reporter should withhold details that enable exploitation.

5. Updates and supported versions

A fix is usually released in the latest version of a supported product line and may require an upgrade rather than a backport. Security updates for products within a statutory support period remain free and available for the required period. See the Support and Lifecycle Policy.

6. Urgent incident

If a vulnerability is actively exploited or creates an immediate risk to data or remote access, use “URGENT / ACTIVE EXPLOIT” in the subject and include time, product, version, indicators, possible impact and containment already taken. Do not send passwords, private keys or unnecessary personal data.

7. Incidents and regulatory duties

N3X assesses and documents incidents and, where legally required, reports an actively exploited vulnerability, severe incident or personal-data breach to the competent authority and informs affected users. A user need not report a product vulnerability on N3X's behalf, but should provide information promptly and preserve evidence.

The operator of a self-hosted N3XRemote, N3XMarket or N3X Remiza instance remains independently responsible for incidents and personal-data breaches in its infrastructure. N3X may help determine whether the cause lies in the product, configuration or environment, but does not become that instance's controller.