Legal

Security Disclosure

We welcome reports from security researchers. This policy explains how to report a vulnerability, what's in scope, and what you can expect from us.

Report a vulnerability
Encrypted email preferred. PGP key available on request.
Email security@nirvet.com

Last updated: 17 July 2026

Nirvet takes the security of our platform and our customers seriously. If you believe you have found a security vulnerability, we want to hear from you and will work with you to understand and resolve it quickly.

How to report

Email security@nirvet.com with enough detail for us to reproduce the issue: affected component or URL, a description of the vulnerability and its impact, and step-by-step reproduction (including any proof-of-concept). Please do not include real customer data in your report.

Safe harbor

We will not pursue or support legal action against researchers who, in good faith, discover and report vulnerabilities in accordance with this policy. Act in good faith, avoid privacy violations and service disruption, and give us a reasonable time to remediate before any public disclosure, and we will treat your research as authorised.

Guidelines

  • Only test against accounts and data you own or are explicitly authorised to test.
  • Do not access, modify, or exfiltrate data that is not yours.
  • Do not run denial-of-service tests, spam, or social-engineering against our staff or customers.
  • Do not publicly disclose a vulnerability until we have confirmed it is resolved and agreed on timing.
  • Stop and report immediately if you encounter customer data.

In scope

The Nirvet platform, its APIs, and this website. Vulnerabilities such as authentication or authorisation flaws, injection, cross-tenant data exposure, SSRF, and sensitive-data handling issues are of particular interest.

Out of scope

  • Findings from automated scanners without a demonstrated, exploitable impact.
  • Reports of missing best-practice headers or configurations with no proven security impact.
  • Social engineering, physical attacks, and denial-of-service.
  • Vulnerabilities in third-party services we do not control.

Our commitments

  • We aim to acknowledge your report within two business days.
  • We will keep you informed as we validate and remediate.
  • We remediate confirmed findings on a risk-tiered schedule, prioritising critical issues.
  • With your permission, we are happy to credit your contribution once the issue is resolved.

We also engage independent third parties for annual penetration testing; scope and methodology are shared with enterprise customers under NDA.