Trust & security

Security and responsible disclosure

How to report a potential security issue privately and responsibly.

Last updated July 21, 2026

Responsible disclosure

If you believe you have found a security vulnerability in a Nexwawe-owned public website or service, report it privately and allow reasonable time for investigation before public disclosure.

What to include

Use the subject “Security report” and include the affected URL or asset, a clear description, reproducible steps, potential impact, and supporting evidence with sensitive values removed.

Safe research expectations

Do not access, modify, download, retain, or disclose data belonging to others. Do not use denial-of-service testing, social engineering, spam, destructive actions, or high-volume scanning. Stop if you encounter personal or confidential information.

Response and scope

We aim to acknowledge credible reports and assess them based on severity and reproducibility, but do not promise a specific response time, reward, or bug bounty. Client-owned and third-party systems are outside this process unless Nexwawe confirms otherwise.

No authorization

This page does not grant permission to test systems unlawfully or outside the boundaries above. Contact us before proceeding if you are uncertain whether an action is safe.

Contact

Questions can be sent to contact@nexwaweinfotech.com. Do not email passwords, private keys, production data, or other secrets.