// SKIP TO CONTENT
NEICRONE
// Security
0405

Vulnerability Disclosure

How to report a security issue to Neicrone, what we commit to in return, and the boundaries of good-faith testing. We would rather hear it from you than from an incident.

// LAST REVIEWED 2026-09-28


Reporting

Email security@neicrone.com. Please do not open a public issue, post publicly, or contact staff individually before we have responded.

Include what you can of:

  • The affected host, endpoint, or component.
  • Reproduction steps, or a minimal proof of concept.
  • What an attacker gets — the impact, in one sentence.
  • Your assessment of severity, and whether you believe it is being exploited.

What we commit to

  • Acknowledgement within 3 business days of your report reaching us.
  • A triage assessment within 10 business days, telling you whether we have reproduced it and the severity we have assigned.
  • Progress updates at least every 14 days while the issue is open.
  • Credit where you want it, once a fix has shipped.

We ask for 90 days before public disclosure, or less by agreement if a fix lands sooner.

In scope

  • neicrone.com and its subdomains.
  • The Andromeda console and its API surface.
  • Authentication, access scoping between engagements, and any path that exposes one partner’s data to another.

Out of scope

  • Findings from automated scanners with no demonstrated impact.
  • Missing hardening headers, cookie flags, or TLS configuration with no working exploit.
  • Rate-limiting, volumetric, or denial-of-service testing. Do not run it.
  • Social engineering of staff, partners, or suppliers, and physical attacks on field hardware or sites.
  • Reports about third-party services we consume, which belong with that provider.

Rules for testing

Stay within your own accounts and data. Do not access, modify, or retain data belonging to anyone else; if you encounter partner data or personal data, stop, do not download it, and tell us what you saw in general terms. Do not degrade the service for others. Use the minimum interaction needed to prove the issue.

Safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised, will not pursue legal action over it, and will say so if a third party raises it with us. If you are unsure whether something is in bounds, ask first at security@neicrone.com.

We do not currently run a paid bounty programme. That may change; the commitments above do not depend on it.