Security
Vulnerability disclosure policy
How to report a security issue safely.
Section 1
Scope
This policy covers nexqlouddrawback.com, run by NexQloud AI Drawback, LLC ('we', 'us'), including the demo and partner-branded pages.
Section 2
Most wanted
Any way to reach data other people sent us through this site, such as waitlist entries, applications or messages.
Section 3
Out of scope
- Denial of service
- Social engineering of staff, clients or partners
- Physical attacks on facilities
- Findings from automated scanners without shown impact
- Third-party services: report to them
Section 4
Rules for testing
- Use the demo and its sample data.
- Do not access, change or keep other people's data.
- Stop and report if you reach real data.
- No public disclosure before we fix the issue.
Section 5
Safe harbor
Good-faith research under this policy is authorized. We will not pursue legal action against it.
Section 6
How to report
Use our contact page and choose the topic "Security".
Our security.txt file points back to this page, in the standard format (RFC 9116).[1]
Include what you found, where, and how to reproduce it.
Section 7
What we commit to
- We reply to your report within 2 business days.
- We triage it and keep you informed.
- We set fix timelines by severity.
- With your permission, we credit you on our thanks page.
Section 8
AMD issues
Report hardware or firmware findings to AMD's product security team. Then tell us, so we can raise our minimum TCB and re-attest.
Section 9
Rewards
We do not offer a paid bounty.