Brand logo of nubesti
  • Home
  • AI Red Team
    • Autonomous Agents

      After KYC and authorization, agents can run scheduled assessments on assets you designate.

    • MITRE ATT&CK mapping

      Testing workflows mapped to MITRE ATT&CK techniques. Mapping is not a claim that every technique ran.

    • OWASP mapping

      Checks mapped to OWASP risk classes, with evidence a reviewer can accept or reject.

    • Integration

      Connect seamlessly with your existing tools and workflows.

    Experience AI Red Team Testing

    See how our autonomous AI agents identify vulnerabilities in your systems.

    Book a Demo
  • Resources
    • Trust Center
    • Methodology
    • Pricing
    • FAQ
    • Blog
  • Contact
    • french
    • spanish
    • portuguese
  • Sign in
  • french
  • spanish
  • portuguese
Sign in
  1. Home
  2. /
  3. Legal
  4. /
  5. Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

How to report a security issue in Nubesti systems, our safe harbor, and what is out of scope.

Last updated: September 21, 2026

Nubesti

1111B S Governors Ave STE 23840
Dover, DE 19904, USA

[email protected]

On this page

  1. 1. How to report
  2. 2. Safe harbor
  3. 3. Out of scope
  4. 4. Coordination
  5. 5. Related pages

If you find a security issue in Nubesti systems (our website, portal, or platform—not a customer target), we want to hear from you. This is the policy referenced by /.well-known/security.txt.

Customer-target findings belong to that customer. Do not send us exploit details about a third party’s production systems.

1. How to report

Email [email protected] with:

  • A clear description and impact
  • Steps to reproduce
  • Affected URL, endpoint, or component
  • Proof that does not destroy data or expose other customers

We aim to acknowledge within 24 hours and give an initial assessment within 48 hours.

2. Safe harbor

We will not pursue civil or criminal action against researchers who:

  • Act in good faith
  • Avoid privacy violations, data destruction, and service degradation
  • Do not access data that is not theirs beyond what is needed to demonstrate the issue
  • Give us a reasonable chance to fix the issue before public disclosure

This safe harbor does not cover attacks on customer environments, physical intrusion, or extortion.

3. Out of scope

  • Denial-of-service or volumetric floods against production
  • Spam, social engineering of staff, or phishing our customers
  • Physical attacks
  • Findings that only affect outdated browsers or require MITM on the researcher’s own machine
  • Issues in third-party products we do not operate, except for a clear misconfiguration we control

4. Coordination

Please do not post a full exploit before we have a fix or have agreed a disclosure date. We are happy to credit researchers who want to be named, unless they prefer to stay anonymous.

We do not currently run a public bug-bounty program. A thank-you or swag may be offered at our discretion; payment is not promised.

5. Related pages

  • Security Overview
  • Acceptable Use Policy
  • Ethics & Reporting

Back to legal center ↗

Brand logo of nubesti

Nubesti LLC provides continuous autonomous security testing against customer-authorized assets. Tests require paid KYC.

  • linkedin

Product

  • Platform
  • Methodology
  • Pricing
  • Demo

Trust

  • Trust Center
  • Platform security
  • Customers
  • Vulnerability disclosure

Legal

  • Legal center
  • Privacy
  • DPA
  • Subprocessors
  • Legal notice
  • About
  • Legal
  • Privacy Policy
  • Legal Notice
  • © 2026 Nubesti LLC
  • All rights reserved