NudgeNudge

Responsible Disclosure

How to report a security issue in Nudge, and how we'll respond.

Last updated: 2 October 2026

We welcome reports from security researchers and users who find a vulnerability in Nudge. If you've found something, please tell us rather than testing further against production.

How to report

Email privacy@nudgeworks.app with a subject line that starts with “Security report:”. Please include:

  • Steps to reproduce the issue
  • The affected URL, endpoint or app screen
  • The impact: what an attacker could do with it

We aim to acknowledge your report within 3 business days and will keep you updated while we work on a fix.

In scope

  • nudgeworks.app and its subdomains, including the web app and the ambassador portal
  • The Nudge apps for iOS and Android
  • Our API and Supabase backend

Rules

  • Only test with accounts you own.
  • Never access, modify or delete other users' data. If you reach someone else's data by accident, stop and report it to us straight away.
  • No denial-of-service, spam, social engineering or physical attacks.
  • No automated scanning that degrades the service for other users.
  • Give us reasonable time to fix the issue (90 days) before any public disclosure.

Out of scope

  • Missing best-practice headers or settings without demonstrated impact
  • Self-XSS
  • Rate-limiting or brute-force reports without demonstrated impact
  • Issues in third-party services we don't control

What we offer

Our thanks and, if you'd like, public credit once the issue is fixed. We don't run a paid bug bounty programme at this time.

Safe harbour

If you follow these rules in good faith, we won't pursue legal action against you and we'll treat your research as authorised. For everything else, our Acceptable Use Policy applies.