Vulnerability Disclosure Policy

Last updated: February 3, 2026

1. Introduction

Nysonik is dedicated to preserving data security by preventing unauthorized disclosure of information. This policy was created to provide security researchers with instructions for conducting vulnerability discovery activities and to provide information on how to report vulnerabilities that have been discovered. This policy explains which systems and sorts of activity are covered, how to send vulnerability reports, and how long we require you to wait before publicly reporting vulnerabilities identified.

2. Guidelines

We request that you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Provide us a reasonable amount of time to resolve the issue before you disclose it publicly.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability's presence. Do not use an exploit to compromise or obtain data, establish command line access and/or persistence, or use the exploit to "pivot" to other systems.
  • Once you've established that a vulnerability exists or encounter any sensitive data (including personal data, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and keep the data strictly confidential.
  • Do not submit a high volume of low-quality reports.

3. Authorization

Security research carried out in conformity with this policy is deemed permissible. We'll work with you to swiftly understand and fix the problem, and Nysonik will not suggest or pursue legal action in connection with your study.

4. Scope

This policy applies to the following systems and services:

  • nysonik.com website
  • Nysonik web application and associated services
  • Any Nysonik services and endpoints hosted at or under nysonik.com

Any service that isn't explicitly specified above, such as related or third-party services, is out of scope and isn't allowed to be tested. Vulnerabilities discovered in third-party solutions Nysonik interacts with are not covered by this policy and should be reported directly to the solution vendor in accordance with their disclosure policy (if any). Before beginning your inquiry, email us at nysonik@nysonian.com if you're unsure whether a system or endpoint is in scope.

5. Types of Testing

The following test types are not authorized:

  • Network denial of service (DoS or DDoS) tests
  • Physical testing (e.g., office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing

6. Reporting a Vulnerability

To report any security flaws, send an email to nysonik@nysonian.com. The next business day, we'll acknowledge receipt of your vulnerability report and keep you updated on our progress. Reports can be anonymously submitted.

7. Desirable Information

In order to process and react to a vulnerability report, we recommend including the following information:

  • Vulnerability description
  • Place of discovery
  • Potential impact
  • Steps required to reproduce a vulnerability (include scripts and screenshots if possible)

If possible, please provide your report in English.

8. Our Commitment

If you choose to give your contact information, we promise to communicate with you in a transparent and timely manner. We will acknowledge receipt of your report within three business days. We will keep you informed on vulnerability confirmation and remedy to the best of our capabilities. We welcome a discussion of concerns and are willing to engage in a discourse.

Contact

For vulnerability reports and scope questions:

Company: Nysonik

Website: https://nysonik.com