About Solutions View all Solutions VisionPulse LaunchIQ Elysium Technology Insights Contact Careers

Vulnerability Disclosure Policy

Last updated: August 27, 2026

We welcome reports from security researchers. If you have found a weakness in something we run, we would rather hear it from you than read about it later. This page sets out what we consider in scope, how to reach us, and what you can expect in return.

1. Scope

The following are in scope:

  • neuvana.ai and www.neuvana.ai — our public website
  • staging.neuvana.ai — our staging environment
  • platform.neuvana.ai — our demonstration platform
  • Any subdomain of neuvana.ai that resolves and serves content we operate

If you are unsure whether something belongs to us, ask before testing. Our DNS has historically used a wildcard record, which means a hostname can resolve without a corresponding service actually existing.

2. Out of scope

These are either not ours to fix or not findings we can act on. Reports limited to the following will be acknowledged and closed:

  • Third-party services we consume but do not operate, including our hosting provider, DNS registrar, and email infrastructure. Report those to the vendor.
  • Denial of service, volumetric testing, or anything that degrades availability for other users.
  • Social engineering of our staff, customers, or suppliers, and any form of physical access testing.
  • Automated scanner output submitted without a demonstrated impact. A tool flagging a missing header is not, by itself, a vulnerability.
  • Missing security headers, cookie flags, or TLS configuration preferences where you cannot show an exploitable consequence.
  • Self-XSS, clickjacking on pages with no state-changing action, and issues that require a fully compromised device or browser.
  • Version-number disclosure without a working exploit against that version.
  • Anything that requires you to hold credentials you were not legitimately issued.

3. How to report

security@neuvana.ai — One report per issue, please.

A report we can act on quickly usually contains:

  • The affected host or URL, and the date and time you tested.
  • Steps to reproduce, written so that someone who has never seen the issue can follow them.
  • What an attacker gains — the impact, stated plainly.
  • Any proof-of-concept code, request captures, or screenshots.

Write in English, Spanish, or Portuguese. If you would prefer to encrypt your report, say so in a first message and we will arrange a key.

4. What we commit to

  • We will acknowledge your report within 5 business days. If you have not heard from us by then, assume the message did not arrive and send it again.
  • We will give you an initial assessment within 10 business days. That means telling you whether we have reproduced the issue and how we have rated it — not necessarily that it is already fixed.
  • We will keep you informed while we work. Remediation timelines depend on severity and on which system is affected. We will tell you what we are doing rather than going quiet.
  • We will tell you when it is fixed, and we are glad to credit you by name when the issue is resolved, if you would like that.

5. Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue legal action against you, and we will not report you to law enforcement, for research conducted within the scope described above.

Good faith means: stop as soon as you have confirmed a vulnerability, access only the minimum data needed to demonstrate it, never modify or delete data that is not yours, never degrade service for anyone else, and never disclose what you found to a third party before we have had a chance to fix it.

If you access personal data belonging to our users or customers in the course of your research, stop immediately, tell us in your report exactly what you saw, and delete your copy. Retaining or sharing that data takes you outside this policy.

6. We do not pay for reports

Neuvana AI does not operate a paid bug bounty programme. We do not pay for unsolicited reports, and we will not respond to invoices, demands for payment, or offers to disclose details in exchange for a fee. Please do not attach an invoice to a disclosure.

This is not a comment on the value of the work. It is a small company being clear about what it can commit to, so that nobody spends their time expecting something we are not offering. What we do offer is a prompt, honest response and public credit if you want it.

7. Coordinated disclosure

We ask that you give us 90 days from your first report before disclosing publicly. In most cases we will be finished well before that, and we are happy to agree a shorter window with you once we understand the issue.

If we disagree about severity or timing, tell us. We would rather have that conversation than discover it in a blog post.

Common questions

How do I report a security vulnerability to Neuvana AI?

Email security@neuvana.ai with the affected host or URL, the date and time you tested, steps to reproduce, and the impact. Send one report per issue. Neuvana AI accepts reports in English, Spanish, and Portuguese, and will arrange encryption on request.

Does Neuvana AI pay for vulnerability reports?

No. Neuvana AI does not operate a paid bug bounty programme and does not pay for unsolicited reports. Invoices, demands for payment, and offers to disclose details in exchange for a fee will not be answered. Researchers are offered a prompt response and public credit instead.

How quickly does Neuvana AI respond to a security report?

Neuvana AI acknowledges reports within 5 business days and gives an initial assessment within 10 business days, stating whether the issue was reproduced and how it was rated. Remediation timelines then depend on the severity and on which system is affected.

Will Neuvana AI take legal action against security researchers?

No, provided the research is in good faith and within the published scope. Neuvana AI will not pursue legal action or report researchers to law enforcement for testing that stops at confirmation, accesses only the minimum data needed, and is not disclosed before a fix.

Which Neuvana AI systems are in scope for security testing?

neuvana.ai, www.neuvana.ai, staging.neuvana.ai, platform.neuvana.ai, and any neuvana.ai subdomain serving content Neuvana AI operates. Third-party services, denial of service, social engineering, and physical access testing are out of scope.

Security contact

security@neuvana.ai

This policy is also linked from our security.txt file. View security.txt