Legal
Responsible disclosure
If you have found a security vulnerability in one of our products or systems, we want to hear about it. This page explains how to report it and what we commit to in return.
In effect from
Our commitment
We take security reports seriously and we treat the people who make them as collaborators rather than as a nuisance. We will not take legal action against anyone who reports a vulnerability in good faith and follows this policy.
Scope
This policy covers:
- the website at neomanera.co.uk;
- software products published by NEOMANERA LTD;
- the online services those products depend on.
It does not cover systems operated by third parties — including application stores, payment providers and hosting platforms. Please report issues in those systems to their own security teams.
How to report
Email [email protected] with “Security” in the subject line. A useful report includes:
- the product, service or URL affected, and the version if applicable;
- a description of the vulnerability and why you believe it is exploitable;
- clear steps to reproduce it, including any request or payload used;
- your assessment of the impact;
- whether any third party is aware of the issue.
Please report in English where you can. If you wish to encrypt your report, write first and we will arrange a key.
Please do not open a public issue, post the details publicly, or demonstrate the vulnerability against real user data before we have had a chance to fix it.
What to expect
| Stage | Our commitment |
|---|---|
| Acknowledgement | Within 2 working days of receipt |
| Initial assessment | Within 10 working days, including our severity view |
| Progress updates | At least every 14 days until the issue is closed |
| Remediation target | 90 days from acknowledgement, and sooner for high-severity issues |
| Disclosure | Coordinated with you once a fix is available |
If we disagree with your assessment, we will explain our reasoning rather than simply closing the report.
Research guidelines
When testing, please:
- use only your own accounts and your own data;
- stop as soon as you have established that a vulnerability exists — do not enumerate records, pivot further into a system, or read other people’s data;
- avoid anything that degrades service for others: no denial-of-service testing, no automated scanning at volume, no spam;
- delete any data you obtained incidentally once you have reported, and tell us what you obtained;
- give us reasonable time to remediate before disclosing publicly.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will regard your activity as authorised, we will not initiate or support legal action against you in relation to it, and we will not report you to law enforcement for it. If a third party brings legal action against you for research that complied with this policy, we will make that compliance known.
This safe harbour does not extend to accessing or exfiltrating other people’s data, to disrupting our services, or to extortion. A report accompanied by a demand for payment in exchange for withholding disclosure is not a security report and will be treated accordingly.
Out of scope
The following are generally not treated as vulnerabilities on their own, though we will still read a report that demonstrates real impact:
- missing security headers with no demonstrated exploit;
- findings from an automated scanner without a working proof of concept;
- reports about software versions, with no demonstrated vulnerable path;
- social engineering of our staff, and physical attacks;
- self-inflicted issues requiring an already-compromised or rooted device;
- email configuration findings — SPF, DKIM, DMARC — with no demonstrated impact;
- absence of rate limiting on an endpoint with no sensitive action behind it.
Recognition
We do not currently operate a paid bug bounty. We do offer public credit: if you would like to be acknowledged for a valid report, tell us the name or handle you would like us to use and we will credit you when we publish the fix. If you would prefer to remain anonymous, that is equally fine.
A machine-readable version of this contact information is published at /.well-known/security.txt.