Vulnerability disclosure
If you’ve found a security issue in the Nebbos substrate, we want to hear about it. This page names the report path and the response you’ll get.
Scope note. Operator-scoped bugs inside your own Nebbos deployment (a stuck task, a mis-classified signal, a Pearl recommendation you disagree with) are not vulnerabilities — those are ordinary support cases handled through your enterprise contact. Vulnerabilities are cross-scope failures or issues in the substrate itself.
Report a vulnerability
Email: security@nebbos.ai PGP key: available on request; we will confirm receipt within one business day.
Please include:
- A description of the issue and its impact
- Steps to reproduce (a short PoC is ideal; a video is welcome but not required)
- The version / URL / endpoint where you observed it
- Whether the issue is being coordinated with any other party
We will not pursue legal action against researchers who report vulnerabilities in good faith and follow the disclosure timeline below. Testing that stays within the scope is authorised.
What happens after you report
Acknowledgement (within 1 business day)
We confirm receipt and open an internal ticket. You get a reference number.
Triage (within 5 business days)
The Nebbos security team reproduces the reported condition, classifies severity per CVSS 3.1, and assigns an owner. Requests for additional information are issued where the report cannot be reproduced from the initial submission.
Fix in flight (severity-dependent)
- Critical — fix in flight within 24 hours; disclosure window starts at fix ship.
- High — fix within 30 days.
- Medium — fix within 90 days.
- Low — bundled with the next planned release.
Coordinated disclosure
You and Nebbos agree on a disclosure date. Default: 90 days after report OR 30 days after fix, whichever is sooner. Extensions are negotiated case-by-case.
Public disclosure
We publish a security advisory, credit the reporter (unless anonymity requested), and (for Critical / High findings) file a CVE.
Scope
In scope:
nebbos.aiand all subdomainsapi.nebbos.ai/api/v1/*endpoints- Nebbos App (macOS, Windows)
- Nebbos SDKs (Python, TypeScript)
- Cradle hardware and firmware
- MCP endpoint and protocol
- Documentation infrastructure (
docs.nebbos.ai)
Out of scope:
- Third-party services listed on the subprocessor list — report directly to those vendors
- Denial-of-service attacks (please don’t try; instead, describe the vector)
- Social-engineering of Nebbos employees or customers
- Physical attacks against Nebbos or customer offices
- Issues in software that Nebbos operators have deployed themselves (report to the operator)
Who this page is for
Nebbos does not run a public bug-bounty programme. The substrate is not accessible to arbitrary researchers — every entry point is gated by operator identity and tier, so surface-level probing produces the same refusal every regulator-facing operation produces. Bugs in the substrate itself surface through internal red-teaming, enterprise pentests, and coordinated disclosures from authorised partners.
If you are an authorised security researcher (retained pentester, coordinated-disclosure partner, government advisory contact), the report path above applies to you. Otherwise, contact your enterprise support representative or enterprise@nebbos.ai for the correct routing.