Trust Center
Responsible disclosure
Report security issues in good faith. We coordinate acknowledgment, remediation, and disclosure timing.
Disclosure steps
From report to coordinated disclosure.
Report
Email nexorbitlabs@gmail.com with a clear description, affected asset, and reproduction steps. Avoid accessing others’ data.
Acknowledge
We acknowledge valid reports promptly and assign a tracking ID for follow-up.
Validate & remediate
We reproduce, rate severity, and remediate based on risk. We may request clarifying details.
Disclose
Coordinated disclosure after a fix is available, or after an agreed timeline when remediation is complex.
In scope and expectations
What to test, what to avoid, safe harbor, timelines, and encrypted submission.
In scope
nexorbitlabs.com, publicly reachable applications we operate, and vulnerabilities with security impact (auth bypass, injection, RCE, significant data exposure).
Out of scope
Social engineering, physical attacks, DoS/spam without impact proof, and issues in third-party services outside our control.
Good-faith research
We welcome good-faith reports that avoid privacy harm and service disruption. Specific legal safe-harbor terms are confirmed with counsel before publication.
Disclosure timeline
Typical remediation window is 90 days for non-critical issues; critical issues are prioritized. We coordinate public disclosure timing with reporters.
PGP
Encrypted reporting available on request — contact nexorbitlabs@gmail.com for current PGP details.
Send reports to nexorbitlabs@gmail.com. Include affected asset, impact, and reproduction steps — and avoid accessing others' data.
Found something?
Email nexorbitlabs@gmail.com with details. We acknowledge valid reports and track remediation.

