Send vulnerability reports to security@nexoratechnologiesnagpur.com — and ask us for a PGP key first if the report contains anything you would not want sitting in a mailbox in plain text.
A useful report includes: the affected endpoint or surface, reproduction steps, sample requests or payloads, observed vs. expected behaviour, and your assessment of impact. Screenshots and PoC code are welcome.
If you prefer encrypted chat or a Signal handoff, email us and we will arrange one.
- Acknowledgement: within 24 hours (1 business day).
- Triage and severity assessment: within 5 business days.
- Remediation target: 30 days for Critical, 60 days for High, 90 days for Medium, 180 days for Low — measured from triage.
- Public disclosure: coordinated. We aim to publish a postmortem within 30 days of remediation for Critical and High findings; you are credited unless you ask not to be.
In scope:
nexoratechnologiesnagpur.comand all*.nexoratechnologiesnagpur.comsubdomains.- The Nexora API (
api.nexoratechnologiesnagpur.com) — REST, WebSocket, and gRPC surfaces. The API is pre-production and not yet open to callers. - Official Nexora SDK packages — TypeScript, Python, Go, Java, Rust, C++ — once published. None is published yet.
- The operations console at
console.nexoratechnologiesnagpur.com.
The following are explicitly out of scope and not eligible for safe harbour. Please don’t test them:
- Denial-of-service or volumetric attacks against any Nexora surface.
- Social-engineering attempts against Nexora, our customers, or vendors.
- Physical attacks against the Nexora office or infrastructure.
- Systems our customers operate — including white-labelled deployments of our products on a customer’s own domain, and software we have built for a customer — unless that customer has authorised your testing. If you find something in one, tell us and we will pass it to them.
- Reports that rely solely on outdated TLS, missing headers, or theoretical issues with no demonstrable impact.
- Findings in third-party infrastructure we use but don’t operate (e.g. cloud provider issues) — please report those to the vendor directly.
Research conducted in good faith under this policy and within scope: Nexora will not pursue legal action, report you to law enforcement, or sue under the Information Technology Act for accessing material inadvertently exposed by a vulnerability you reported. We will work with you to understand and remediate the issue. If a third party brings action against you for research conducted under this policy, we will make our authorisation clear.
We do not run a paid bounty programme yet, and we would rather say so than publish a table we cannot stand behind. What we can offer today is a real response from someone who can act on the report, public credit if you want it, and the safe harbour set out above. If you find something serious, tell us anyway — and if a programme starts later, reporters who helped before it existed will not be forgotten.
Reach us at security@nexoratechnologiesnagpur.com. The same address is documented at /.well-known/security.txt.