Responsible Disclosure
How to report a security issue in Nudge, and how we'll respond.
We welcome reports from security researchers and users who find a vulnerability in Nudge. If you've found something, please tell us rather than testing further against production.
How to report
Email privacy@nudgeworks.app with a subject line that starts with “Security report:”. Please include:
- Steps to reproduce the issue
- The affected URL, endpoint or app screen
- The impact: what an attacker could do with it
We aim to acknowledge your report within 3 business days and will keep you updated while we work on a fix.
In scope
- nudgeworks.app and its subdomains, including the web app and the ambassador portal
- The Nudge apps for iOS and Android
- Our API and Supabase backend
Rules
- Only test with accounts you own.
- Never access, modify or delete other users' data. If you reach someone else's data by accident, stop and report it to us straight away.
- No denial-of-service, spam, social engineering or physical attacks.
- No automated scanning that degrades the service for other users.
- Give us reasonable time to fix the issue (90 days) before any public disclosure.
Out of scope
- Missing best-practice headers or settings without demonstrated impact
- Self-XSS
- Rate-limiting or brute-force reports without demonstrated impact
- Issues in third-party services we don't control
What we offer
Our thanks and, if you'd like, public credit once the issue is fixed. We don't run a paid bug bounty programme at this time.
Safe harbour
If you follow these rules in good faith, we won't pursue legal action against you and we'll treat your research as authorised. For everything else, our Acceptable Use Policy applies.