Vulnerability Disclosure Policy
Nebli, Inc. ("Nebli", "we", "us") welcomes reports from security researchers who find vulnerabilities in our systems. This policy describes what we ask of researchers, what you can expect from us, and the scope of systems this policy covers.
Scope
In scope: the nebli.ai website and its subdomains, the Nebli dashboard and customer-facing web applications, and Nebli's public APIs.
Out of scope: third-party services we integrate with but do not operate (payment processors, analytics providers, cloud infrastructure vendors); physical attacks against drones, cameras, sensors, or other field hardware; social engineering or phishing directed at Nebli staff, contractors, or customers; and any testing that could disrupt service for other customers, including denial-of-service testing and automated scanning at volume.
What we can authorize
We can authorize testing only of Nebli's own systems and data. This policy does not authorize, and we cannot authorize, testing that accesses, alters, or affects another customer's data, accounts, or tenant, other users, or our infrastructure providers' systems. If a test would reach data that is not yours and not ours, stop and contact us and we will arrange a safe way to demonstrate the issue. Accessing data beyond this is outside this policy's safe harbor and may violate data-protection laws, which we cannot waive on behalf of the people whose data it is.
Reporting a vulnerability
Email security@neblihq.com with a description of the issue, the steps to reproduce it, and its potential impact. Include enough detail for us to reproduce the finding; proof-of-concept code is welcome and should be limited to what is necessary to demonstrate the issue.
Our commitment
We will acknowledge your report, investigate in good faith, and keep you informed of our progress. We ask that you give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly, and that you avoid accessing, modifying, or deleting data that does not belong to you beyond what is necessary to demonstrate the vulnerability.
If you encounter personal data, stop, and do not download, copy, retain, or share it; access only the minimum needed to demonstrate the issue, and delete any incidental copies once you have reported. If a report indicates personal data may have been exposed, we may be required to notify affected individuals, our customers, or regulators, and we ask for your cooperation in establishing what was accessed.
Safe harbor
We will not pursue legal action against researchers who discover and report a vulnerability in good faith and in accordance with this policy, provided the research stays within the scope described above. To the extent your research complies with this policy, we also waive any restriction in our Terms of Service that would otherwise prohibit it. We will not contact your employer, client, or educational institution about research conducted under this policy, and reporting a vulnerability will never itself be treated as a hostile act. If you make a good-faith effort to comply and get scope wrong, we will treat that as authorized conduct rather than a violation.
Recognition
We do not currently run a paid bug bounty program. With your permission, we're glad to credit researchers who report a valid vulnerability once it has been remediated.