Your tests stay Playwright, Selenium and pytest. We don't replace them. We make them enterprise-ready, and you own everything: code, evidence and history.

Security

Last updated 2026-10-01 · how to report a vulnerability in Nexus Studio or our services

If you find a security problem in Nexus Studio, this website or the account portal, please tell us. This page says how, what is in scope, and what we commit to in return. It is about our software and our systems only: it does not authorize testing anyone else's. How the product handles your data is in Security and privacy.

How to report

Email [email protected] with:

We have no encryption key published yet. If a report is too sensitive for plain email, write first and we will agree a channel. Our security.txt carries the same contact.

In scope

Out of scope

What we ask of you

What we commit to

There is no paid bounty today. A report that demands payment, or threatens disclosure to get something, is not research, and the good-faith commitment does not apply to it.

Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorized, and:

This authorization covers only our systems in scope above. We cannot authorize testing of our providers or our customers. If you are unsure whether something is in scope, ask us first at [email protected].

How fixes reach installations

Nexus Studio runs on our customers' machines, so we cannot patch an installation ourselves. We ship a release, and the Studio announces it at its next license check; installing it is the customer's step. We can tell you when a fix has shipped, never that every installation has it. Fixes to the website, the portal and the license service apply as soon as we deploy them.

Security advisories and notifications

If we learn that a vulnerability in Nexus Studio is being actively exploited, or of an incident that affects its security, we report it to the authorities the law requires, including through the EU Single Reporting Platform under the Cyber Resilience Act. We email every account holder whose installation is affected, with what the issue is and what to do, and we publish an advisory on this page once a fix or a mitigation is available.