./security
Responsible disclosure
Found a vulnerability? Tell us privately first. We'll respond within 48 hours, triage within 5 business days, and credit you on the hall of fame if you wish.
./contact
Email security@veilnebu.la with reproduction steps and impact.
For sensitive reports, ask us for a PGP key in your first (unencrypted) mail and we will reply with one before you send details. Our security.txt carries the current contact addresses.
./scope
In scope:
api.veilnebu.la+ subdomainsapp.veilnebu.la+ subdomains- Telegram bot
@nebulapay_bot - SDK code under
npm i @nebula/* - Webhook delivery + signature handling
- HD wallet derivation, payout signing, audit chain
Out of scope:
- Marketing/landing pages outside the listed hosts
- Third-party vendor (AMLBot, Chainalysis) issues — report direct
- Social engineering of staff
- Volumetric DoS / load testing
./severity-matrix
| Severity | Examples | Reward (USD) |
|---|---|---|
| Critical | RCE, vault key disclosure, signer compromise, audit chain forgery | 10,000–50,000 |
| High | SSRF on webhook delivery, IDOR on cross-merchant data, bypass of MFA | 2,500–10,000 |
| Medium | Stored XSS, rate-limit bypass, leaked PII, weak crypto on non-secret fields | 500–2,500 |
| Low | Reflected XSS w/ user interaction, missing security headers, info disclosure | 100–500 |
Final award at our discretion. Duplicates pay the first valid reporter. Reports without repro steps will be rejected.
./rules
- Test only against your own merchant account or the public sandbox
- Stop on first proof — do not exfiltrate data
- Give us 90 days from initial report before public disclosure
- No automated scanners that generate >5 req/s sustained
./hall-of-fame
Researchers who have helped us harden the platform:
- — None yet. Be first.