./security

Responsible disclosure

Found a vulnerability? Tell us privately first. We'll respond within 48 hours, triage within 5 business days, and credit you on the hall of fame if you wish.

./contact

Email security@veilnebu.la with reproduction steps and impact.

For sensitive reports, ask us for a PGP key in your first (unencrypted) mail and we will reply with one before you send details. Our security.txt carries the current contact addresses.

./scope

In scope:

  • api.veilnebu.la + subdomains
  • app.veilnebu.la + subdomains
  • Telegram bot @nebulapay_bot
  • SDK code under npm i @nebula/*
  • Webhook delivery + signature handling
  • HD wallet derivation, payout signing, audit chain

Out of scope:

  • Marketing/landing pages outside the listed hosts
  • Third-party vendor (AMLBot, Chainalysis) issues — report direct
  • Social engineering of staff
  • Volumetric DoS / load testing
./severity-matrix
SeverityExamplesReward (USD)
CriticalRCE, vault key disclosure, signer compromise, audit chain forgery10,000–50,000
HighSSRF on webhook delivery, IDOR on cross-merchant data, bypass of MFA2,500–10,000
MediumStored XSS, rate-limit bypass, leaked PII, weak crypto on non-secret fields500–2,500
LowReflected XSS w/ user interaction, missing security headers, info disclosure100–500

Final award at our discretion. Duplicates pay the first valid reporter. Reports without repro steps will be rejected.

./rules
  • Test only against your own merchant account or the public sandbox
  • Stop on first proof — do not exfiltrate data
  • Give us 90 days from initial report before public disclosure
  • No automated scanners that generate >5 req/s sustained
./hall-of-fame

Researchers who have helped us harden the platform:

  • — None yet. Be first.
Security · VeilNebula