Security
We take reports seriously.
Nimbus Vault is built for security researchers — so we hold ourselves to the standard we would expect from the tools we use. This page explains how to report a vulnerability, what we commit to in return, and our safe-harbor commitment for good-faith research.
Report a vulnerability01 Our commitment
We welcome reports about the security of Nimbus Vault — the workspace app, our backend, and the Chrome extension. If you find a vulnerability, we want to hear about it, and we will treat you as a partner in fixing it, not as an adversary.
02 Scope
In scope:
- workspace.nimbusvault.app — the Nimbus Vault workspace app.
- nimbusvault.app — this website.
- Backend services — the Convex-powered API that the app and extension use.
- The Nimbus Vault Chrome extension.
Out of scope:
- Denial-of-service, brute-force, or volumetric attacks, and automated scanner output without a demonstrated impact.
- Social engineering, phishing, or physical attacks against our team.
- Vulnerabilities in third-party providers (Clerk, Convex, Vercel, Cloudflare, or your AI provider) — please report those upstream.
- Vulnerabilities in systems you are researching with Nimbus Vault — those belong to the target and its disclosure program.
- Issues that require an already-compromised device or account, or that rely on unrealistic user interaction.
03 How to report
Email [email protected] with:
- a description of the issue and the impact you believe it has;
- the steps to reproduce it (proof-of-concept welcome);
- the affected URL, component, or extension version;
- how you would like to be credited, if at all.
Please include only the data necessary to demonstrate the issue, and delete any data you access as part of your testing once we confirm the fix. We may follow up with questions to understand and reproduce the report.
04 What we commit to
- Acknowledge your report within 3 business days.
- Investigate promptly and keep you updated on our assessment and progress.
- Fix valid issues as quickly as severity warrants, and tell you when it is resolved.
- Credit you (with your permission) once the issue is resolved.
- Coordinate disclosure — we are happy to agree on a disclosure timeline together; absent an agreement, we ask for 90 days before public disclosure.
05 Safe harbor
We consider security research conducted in good faith under this policy to be authorized. We will not initiate legal action against you for researching or reporting a vulnerability under this policy, and if a third party brings legal action against you for such research, we will make this authorization clear.
Good faith means: you stay within the scope above; you avoid privacy violations, data destruction, and service disruption; you do not extort us; and you give us reasonable time to fix the issue before public disclosure. Activity outside this policy is not authorized. This policy does not bind third parties and covers only systems we control.
06 Bounty status
We do not currently offer paid bounties. Valid reports are still very welcome, and with your permission we are glad to credit you. If we launch a bounty program, we will announce it on this page.
07 Contact
[email protected] — machine-readable contact details are in /.well-known/security.txt.