// responsible disclosure
Responsible disclosure policy
Security researchers help keep NeoShield safe. If you find a vulnerability, please report it to us privately and give us a reasonable chance to fix it before disclosing it publicly. We appreciate good-faith research and will work with you.
How to report
Email security@neoshieldsecurity.com (the same address is published in our security.txt). Include a clear description, the steps to reproduce, the impact, and any proof-of-concept. Please report privately — don't post the issue publicly until we've had a chance to address it.
Scope
- neoshieldsecurity.com
- The public web application
- Public APIs, where applicable
Safe harbor
We consider good-faith security research conducted under this policy to be authorized. We won't pursue action against researchers who follow these rules, act in good faith, and avoid privacy violations, data destruction, or service disruption. If you're unsure whether something is allowed, ask us first.
Rules — allowed
- Good-faith testing intended to find and report vulnerabilities.
- Testing only against your own account and your own data.
- Detailed, private reporting that gives us time to remediate.
Rules — not allowed
- Denial-of-service or any test that degrades or disrupts the service.
- Social engineering of our staff, users, or vendors.
- Physical attacks against people or property.
- Accessing, modifying, or destroying other users' data.
- Data exfiltration.
- Automated scanning that disrupts the service or generates excessive load.
What to expect
- We aim to acknowledge your report within 7 business days.
- We aim to remediate validated issues within 90 days where reasonably possible, and we'll keep you updated on progress.
- With your permission, we're happy to credit you once an issue is resolved.
Out of scope
Reports that typically won't qualify: missing best-practice headers with no demonstrated impact, rate-limiting or volumetric issues, social-engineering findings, results from disruptive automated scanners, and vulnerabilities in third-party services (Stripe, Anthropic, Google) that we don't control — please report those to the relevant vendor.
This policy describes our intent for good-faith research; it is not a contract and may be updated as the platform evolves.