Legal

Vulnerability Disclosure Policy

Last updated June 16, 2026

We welcome reports from security researchers. This policy describes how to report a vulnerability in SecNxt, what is in scope, and our commitments to you.

1. Scope

This policy covers SecNxt's public websites, marketing pages, and the SecNxt console and APIs operated by us. Third-party services we integrate with are out of scope and should be reported to their respective owners.

2. How to report

Send a detailed report to security@secnxt.ai, or use the Contact page. Please include steps to reproduce, affected URLs or endpoints, and any proof-of-concept. Encrypt sensitive details where possible.

3. Safe harbor

If you make a good-faith effort to comply with this policy, we will not pursue legal action against you. Act in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure.

4. What we ask

Do not access, modify, or delete data that is not yours. Do not run automated scans that degrade service. Do not use social engineering, phishing, or physical attacks. Only test accounts and data you own or are authorized to test.

5. Our commitment

We will acknowledge your report promptly, keep you updated on remediation progress, and credit you (with your permission) once the issue is resolved. We aim to triage critical reports within a few business days.

6. Contact

Reach our security team at security@secnxt.ai. SecNxt is a product of Olwayz24 Technologies Pvt. Ltd.