Security

Vulnerability disclosure policy

How to report a security issue safely.

Section 1

Scope

This policy covers nexqlouddrawback.com, run by NexQloud AI Drawback, LLC ('we', 'us'), including the demo and partner-branded pages.

Section 2

Most wanted

Any way to reach data other people sent us through this site, such as waitlist entries, applications or messages.

Section 3

Out of scope

  • Denial of service
  • Social engineering of staff, clients or partners
  • Physical attacks on facilities
  • Findings from automated scanners without shown impact
  • Third-party services: report to them

Section 4

Rules for testing

  • Use the demo and its sample data.
  • Do not access, change or keep other people's data.
  • Stop and report if you reach real data.
  • No public disclosure before we fix the issue.

Section 5

Safe harbor

Good-faith research under this policy is authorized. We will not pursue legal action against it.

Section 6

How to report

Use our contact page and choose the topic "Security".

Our security.txt file points back to this page, in the standard format (RFC 9116).⁠[1]

Include what you found, where, and how to reproduce it.

Section 7

What we commit to

  • We reply to your report within 2 business days.
  • We triage it and keep you informed.
  • We set fix timelines by severity.
  • With your permission, we credit you on our thanks page.

Section 8

AMD issues

Report hardware or firmware findings to AMD's product security team. Then tell us, so we can raise our minimum TCB and re-attest.

Section 9

Rewards

We do not offer a paid bounty.

Demo

Run the demo

Watch the agent turn a sample file into a claim folder. About 3 minutes.

We'll email you the link and add you to the waitlist. Unsubscribe anytime. We never ask for your ACE login or bank details.