Security

Vulnerability disclosure policy

We want everything we build to be secure. If you believe you’ve found a security vulnerability in one of our systems, please email security@nextinstruction.com.

Last updated

How to report

Email your report to security@nextinstruction.com. To help us understand the problem quickly, please include:

  • what the vulnerability is and where you found it;
  • step-by-step instructions to reproduce it;
  • what you think someone could do with it.

Our security contact details are also published in our security.txt file.

Scope

This policy covers nextinstruction.com and all of its subdomains.

Some of our services run on systems operated by other companies. This policy can’t authorize testing of those systems, so please report problems in them to the company that runs them.

Out of scope

The following aren’t covered by this policy or its safe harbor, so please don’t attempt them:

  • social engineering of any kind, such as phishing;
  • denial-of-service attacks, or any testing that disrupts or degrades our services;
  • physical attacks against people, property, or equipment;
  • any testing that accesses, changes, or deletes other people’s data. Only use accounts and data that belong to you.

Testing in good faith

While you research, please:

  • report a vulnerability as soon as you can after finding it;
  • do only what’s needed to confirm the problem, and don’t use it to reach more data or other systems, or to keep access;
  • stop if you come across anyone else’s information, don’t save or share it, and tell us right away;
  • give us reasonable time to fix the problem before you share details publicly.

Safe harbor

If you make a good-faith effort to follow this policy, we’ll consider your research authorized, and we won’t pursue or support legal action against you because of it. If someone else takes legal action against you for research that followed this policy, we’ll make it known that your research was authorized.

Not sure whether something is allowed? Email us before you go ahead.

What to expect

We’ll acknowledge your report within 5 business days. After that, we’ll do our best to keep you updated as we look into it.

We don’t offer a bug bounty or other payment for reports at this time.

Thank you for helping us build safer software.