Nuaj Company Inc. builds security software. We would rather hear about a weakness from you than read about it somewhere else, and we treat a report as a contribution rather than an accusation. This page sets out what is in scope, what we commit to, and what we ask of you.
Report to
security@nuaj.comEnglish or French. Please do not open a public issue before we have replied.
Scope
In scope:
nuaj.comand its subdomains, includingprotect.nuaj.comanddownload.nuaj.com;- the NuajProtect server, dashboard, API, and endpoint agents;
- NuajLens;
- NuajBridge appliance firmware and its provisioning flow;
- the packages and update artefacts we publish, and the signatures over them.
Out of scope:
- findings that require physical access to a device you do not own, or a compromised account you were given;
- denial of service, traffic flooding, and resource-exhaustion testing against our production systems — tell us the weakness rather than demonstrating it at our expense;
- social engineering of our staff, customers, or suppliers, and any form of phishing;
- reports produced solely by an automated scanner with no demonstrated impact, including missing headers or cookie flags on pages carrying no session;
- weaknesses in third-party services we consume, which should go to that vendor — though we would still like to know;
- a customer's own self-hosted deployment, unless the weakness is in our software rather than their configuration.
What we commit to
- We acknowledge a report within 3 business days.
- We give an initial assessment, including whether we consider it in scope and our severity view, within 10 business days.
- We keep you updated at least every 14 days until the issue is closed.
- We aim to remediate critical issues within 30 days, and others on a schedule we will state and explain.
- We will credit you by name or handle in the release notes if you would like that, and will just as happily keep you anonymous.
- We will tell you when the fix ships, so you can verify it.
We do not currently operate a paid bug bounty. If that changes we will say so here.
What we ask
- Give us enough detail to reproduce it: the affected component and version, the steps, and what an attacker gains.
- Use the minimum access needed to demonstrate the issue. Do not read, alter, or retain anyone else's data; if you encounter personal information, stop and tell us.
- Do not degrade the service for others, and do not run destructive tests.
- Give us a reasonable chance to fix it before publishing. We suggest 90 days from acknowledgement, and are happy to agree something shorter for a low-impact issue or longer for one that is hard to fix safely. If we go quiet, that is our failure — not a reason to stay silent forever.
Safe harbour
If you make a good-faith effort to follow this policy, we will treat your research as authorised. We will not pursue or support civil or criminal action against you, and if a third party brings action over activity that complied with this policy, we will say publicly that it was authorised.
This authorisation is ours to give only for systems we own. It does not extend to a customer's self-hosted deployment or to any third party's infrastructure, and it does not waive their rights. If you are unsure whether something is ours, ask us first at security@nuaj.com — we will answer quickly.
Good faith means the whole of it: acting within scope, stopping when you hit someone else's data, and not using a finding for extortion or leverage.
How we handle your report
A report and the correspondence around it are handled under our Privacy Policy. We keep reports for as long as needed to fix the issue, verify the fix, and record what happened. If a report reveals a breach affecting personal information, the notification obligations described in the Privacy Policy apply.
Machine-readable contact
The same contact details are published at /.well-known/security.txt, per RFC 9116.