Security
Vulnerability Disclosure & Bug Bounty
Security researchers: thank you for looking at Nexus Legal with a critical eye. This page describes our disclosure policy, the authorized scope, and the rewards. Stable document, last updated 2026-05-21.
How to report
Send an email to security@nexusquantum.legal. PGP encryption is optional: request the public key in the same email and we will send it signed.
For machines: https://legal.nexusquantum.legal/.well-known/security.txt (RFC 9116).
Acknowledgement within 72 hours. Triage and response plan within 7 calendar days. Final notification of the fix within ≤ 90 days from the report for High/Critical severities.
Authorized scope
In scope
legal.nexusquantum.legal— main application.api.nexusquantum.legal(if exposed) and routes/api/v1/*.- Published SDKs:
@nexus-legal/sdk(npm),nexus-legal(PyPI). - MCP server
@nexus-legal/mcp(npm). - Billing, credits, multi-tenancy, and sub-key isolation logic.
- Any route listed in the public specification /api/v1/openapi.json.
Out of scope
- DDoS, volumetric attacks, or brute-force resource exhaustion.
- Social engineering against employees or customers.
- Physical access to offices or infrastructure.
- Third-party vulnerabilities that have not been modified by Nexus (e.g. a generic Next.js CVE without a demonstration of exploitation on our surface).
- SPF/DMARC/DKIM improvements (we will address them but they do not qualify for a reward).
- UI bugs with no security impact (rendering, accessibility).
- Automated scans (Nessus, Acunetix) without manual verification of the finding.
Rewards (pilot program)
Program in pilot phase. Rewards at Nexus's discretion based on CVSS v3.1 severity, report quality, and novelty. No payment for duplicates or for findings already known internally.
| Severity | Range (EUR) | Examples |
|---|---|---|
| Critical | 500 – 2 000 | RCE, global auth bypass, mass exfiltration of customer data. |
| High | 200 – 500 | Cross-tenant privilege escalation, billing bypass, SQL injection. |
| Medium | 50 – 200 | Cross-tenant information leak, persistent XSS with sensitive context. |
| Low | Hall of Fame | Low-impact misconfigurations, missing header, cosmetic improvement. |
Safe harbor
If you act in good faith following this policy:
- We will not pursue civil or criminal legal action against you.
- We will not report you to the authorities for your testing activity.
- We will work with you to understand and resolve the issue quickly.
- We will publicly acknowledge you in the Hall of Fame if you wish.
Basic rules: do not access other customers' data beyond what is necessary to demonstrate the finding; do not degrade the service (DoS/load); do not exfiltrate data; report as soon as you detect the vulnerability; keep it confidential until we confirm the public fix.
Hall of Fame
There are no valid external reports yet. Be the first — we will list you here with your name or public handle.