Reporting
Report first. Protect people and data.
Where to report
Send a clear report to dwayneoneill@nightfalltechnologies.com with “Security Report” in the subject. Include the affected page or component, steps to reproduce, impact, and supporting screenshots or logs with sensitive information removed.
Research boundaries
- Test only systems and accounts you own or have explicit authorization to test.
- Do not access, alter, retain, or disclose another person’s data.
- Do not use denial-of-service, destructive testing, social engineering, spam, physical intrusion, or extortion.
- Stop when a vulnerability is confirmed and give NightFall reasonable time to investigate.
- Do not publicly disclose an unresolved issue without coordinating a responsible timeline.
What to expect
NightFall will make a good-faith effort to acknowledge credible reports, assess severity, request clarification when needed, and communicate material remediation progress. This policy does not promise payment or create a bug-bounty program.
Scope
Until specific product testing programs are announced, this process covers the public NightFall Technologies website and only those NightFall-controlled systems explicitly identified in writing. Project names on this website do not authorize testing private repositories, personal accounts, infrastructure, or third-party services.
