generated: '2026-08-26' method: searched source: https://nexla.com/responsible-disclosure-policy/ program: type: responsible-disclosure bug_bounty: false bounty_platform: null policy_url: https://nexla.com/responsible-disclosure-policy/ effective_date: '2021-07-14' contact_email: security@nexla.com security_txt: false commitments: - 'We will acknowledge your email within 24 hours.' - 'We aim to resolve critical issues within 10 days of disclosure.' - 'Provide us with a reasonable amount of time to resolve the issue before disclosing it to the public or a third party.' researcher_rules: - 'Make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Nexla service.' - 'Please only interact with accounts you own or for which you have explicit permission from the account holder.' notes: >- No /.well-known/security.txt is served on nexla.com, docs.nexla.com or dataops.nexla.io (all probed — see well-known/nexla-well-known.yml). The disclosure route is the published policy page and the security@nexla.com mailbox. No public bug bounty (HackerOne/Bugcrowd/Intigriti) was found. evidence: - url: https://nexla.com/responsible-disclosure-policy/ status: 200 - url: https://nexla.com/.well-known/security.txt status: 404