Vulnerability Disclosure Policy
Last updated: 3rd August 2026
We take security seriously and welcome reports from security researchers acting in good faith. This policy explains what's in scope, how to report a vulnerability, and what protection you have for reporting responsibly.
1. Scope
This policy covers:
- The NSOffice.AI platform, including the Think, Know, and Do capabilities, our website, and our API endpoints.
- Our Connectors and Bees, to the extent the vulnerability exists in our own implementation rather than in a third party system we connect to.
- Attempts to bypass or manipulate our guardrails layer, since guardrails are a security control, not just a content filter.
Out of scope:
- Third party systems you connect through a Connector, such as your organization's own email, CRM, or ERP provider. Report those issues to the relevant provider directly.
- The underlying AI model providers themselves. If you find a vulnerability in an AI provider's own infrastructure rather than in how we integrate with it, report it to that provider.
- Denial of service testing, spam, social engineering of our staff, or physical attempts to access our facilities.
- Automated scanning that generates high volumes of traffic without prior coordination with us.
2. Rules for Testing
Because NSOffice.AI is a multi tenant platform, the following rules apply in addition to standard good practice:
- Only test using an account and organization you control. Do not attempt to access, modify, or view another organization's data, even to demonstrate a vulnerability.
- If a vulnerability could expose another organization's data, stop testing immediately and report it to us with only the minimum information needed to demonstrate the issue.
- Do not exfiltrate, download, or retain any data you were able to access as a result of a vulnerability, beyond what is strictly necessary to report it.
- Do not disrupt service availability for other customers.
3. Reporting a Vulnerability
Email customersupport@nsoffice.ai with a clear description of the issue, the steps to reproduce it, and its potential impact. Please include enough detail for us to reproduce the issue without needing to ask follow up questions where possible, and please do not publicly disclose a vulnerability before we've had a reasonable opportunity to investigate and address it.
4. What We Ask
- Give us a reasonable time to investigate and remediate before any public disclosure.
- Act in good faith and avoid privacy violations, data destruction, or service disruption while testing.
- Do not use a vulnerability to access more data or systems than necessary to demonstrate the issue.
5. Our Commitment
- We will acknowledge your report within 2 business days.
- We will keep you informed of our progress in addressing the issue, at a level of detail appropriate to the finding.
- We will let you know once the issue has been resolved, and, with your permission, credit you publicly for responsible reporting.
- We do not currently offer a paid bug bounty program, but we recognize good faith research and take every credible report seriously.
Once a report is confirmed, we prioritize remediation based on severity and potential impact, and will keep you updated on our progress.
6. Safe Harbor
We will not pursue legal action against a researcher who makes a good faith effort to comply with this policy, including any activity that might otherwise be restricted under our Usage Policy or Terms of Service, provided the rules in Sections 1 and 2 above are followed. If legal action is initiated by a third party against you for activity conducted in accordance with this policy, we will make it known that your actions were authorized by us.
7. Changes to This Policy
We may update this policy from time to time. We will update the date above when we do.