The security of The Nexment Project, our users, contributors, and infrastructure is important to us.
If you discover a security vulnerability in a Nexment project, service, website, or other official infrastructure, please report it responsibly.
Please do not publicly disclose or create a public issue for a security vulnerability.
Send your report to:
Please include as much relevant information as possible, such as:
- The affected project, service, or website.
- A clear description of the vulnerability.
- Steps required to reproduce the issue.
- The potential impact.
- Proof-of-concept code or screenshots, when appropriate.
- Any other information that may help us investigate the issue.
You do not need to have a complete fix before reporting a vulnerability.
After receiving a security report, we will:
- Review the report and determine whether it represents a security issue.
- Investigate and attempt to reproduce the reported behavior.
- Assess the potential impact.
- Take appropriate steps to mitigate or fix the issue.
- Communicate with the reporter when additional information is required.
Response and resolution times may vary depending on the complexity and severity of the issue.
Please allow us reasonable time to investigate and address a vulnerability before publicly disclosing it.
Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate the issue.
Do not access, modify, delete, or expose data belonging to other users.
Do not intentionally disrupt Nexment services or infrastructure.
Do not use a security vulnerability to harm other people or systems.
This policy applies to security vulnerabilities affecting The Nexment Project, including:
- Nexment software and open-source projects.
- Nexment websites and services.
- Nexment infrastructure.
- Nexment Dev Community.
- Nexment Academy.
- Official APIs and integrations.
- Other systems officially operated by The Nexment Project.
Individual repositories may provide additional security instructions. If they do, follow the instructions provided by that repository.
The following generally do not qualify as security vulnerabilities unless they demonstrate a meaningful security impact:
- General feature requests.
- Non-security bugs.
- Cosmetic issues.
- Spam.
- Social engineering attempts against Nexment personnel.
- Issues affecting third-party services that are outside Nexment's control.
If you are unsure whether an issue is security-related, contact us anyway.
We appreciate responsible security research.
Researchers who follow this policy, avoid unnecessary harm, and report vulnerabilities responsibly should not be discouraged from reporting security issues to us.
We ask researchers to respect user privacy, avoid accessing data that does not belong to them, and stop testing once enough information has been obtained to demonstrate the vulnerability.
Security is a shared responsibility.
If you find something that could put Nexment or its users at risk, please tell us privately so we can investigate and address it.
Security reports: [email protected]