Security
Last updated 2026-10-01 · how to report a vulnerability in Nexus Studio or our services
If you find a security problem in Nexus Studio, this website or the account portal, please tell us. This page says how, what is in scope, and what we commit to in return. It is about our software and our systems only: it does not authorize testing anyone else's. How the product handles your data is in Security and privacy.
How to report
Email [email protected] with:
- what the issue is, and what an attacker could achieve with it;
- the version of Nexus Studio, or the address, it affects;
- the fewest steps that reproduce it;
- your name or handle, if you want credit.
We have no encryption key published yet. If a report is too sensitive for plain email, write first and we will agree a channel. Our security.txt carries the same contact.
In scope
- Nexus Studio: the Studio, its engine, its command-line tool and the installer, in a version you obtained lawfully.
- This website, the account portal under
/appand the license service under/v1, on our own domain.
Out of scope
- Our customers' systems and installations. Report a problem there to that customer. We have no access to their machines and cannot act on it.
- Our providers, such as Cloudflare, Stripe, Resend, Google and GitHub. Report to them directly; tell us too if it affects us.
- Denial of service, load testing or spam against our services, and social engineering or physical access against us.
- Anything reached by testing a system you were not authorized to test.
What we ask of you
- Give us reasonable time to fix the issue before you disclose it. We ask for 90 days, and we will tell you if we need longer and why.
- Use only the access needed to show the issue, and stop there. Use accounts you created yourself; never another person's account, data or card.
- Do not access, change, delete or copy data that is not yours. A screenshot of a record you can reach is proof; a copy of the database is not.
- Do not degrade our services for other people.
What we commit to
- Acknowledge your report within 5 business days.
- Assess it and tell you whether we consider it a vulnerability, and how we plan to handle it, within 15 business days.
- Keep you informed while we fix it, and tell you when the fix ships.
- Credit you in the release notes, if you want it and the report was valid.
There is no paid bounty today. A report that demands payment, or threatens disclosure to get something, is not research, and the good-faith commitment does not apply to it.
Safe harbor
If you make a good-faith effort to follow this policy, we consider your research authorized, and:
- we will not pursue or support any legal action against you for it, civil or criminal, including under the Computer Fraud and Abuse Act, state computer crime laws, the UK Computer Misuse Act or similar laws elsewhere;
- we waive any claim under section 1201 of the DMCA, or similar anti-circumvention laws, for circumventing the license check or other technical measures in Nexus Studio to research it, and we waive the restrictions in our Terms, our Acceptable Use Policy and the LICENSE file that would otherwise forbid that research, such as reverse engineering or bypassing the license check. Both waivers apply only on a copy you obtained lawfully, only for research within this policy, and only while you do not publish, share or sell a tool, patch, key or method that defeats the license check, and do not use a circumvented copy for anything but the research. They do not cover trafficking in circumvention tools;
- if a third party brings a claim against you over research within this policy, we will make it known that you acted under it.
This authorization covers only our systems in scope above. We cannot authorize testing of our providers or our customers. If you are unsure whether something is in scope, ask us first at [email protected].
How fixes reach installations
Nexus Studio runs on our customers' machines, so we cannot patch an installation ourselves. We ship a release, and the Studio announces it at its next license check; installing it is the customer's step. We can tell you when a fix has shipped, never that every installation has it. Fixes to the website, the portal and the license service apply as soon as we deploy them.
Security advisories and notifications
If we learn that a vulnerability in Nexus Studio is being actively exploited, or of an incident that affects its security, we report it to the authorities the law requires, including through the EU Single Reporting Platform under the Cyber Resilience Act. We email every account holder whose installation is affected, with what the issue is and what to do, and we publish an advisory on this page once a fix or a mitigation is available.