Vulnerability Disclosure Policy

    Last updated: August 28, 2026

    The security of our platform, our AI agents, and our customers' data is our highest priority. We encourage and value collaboration with security researchers, ethical hackers, and the broader community to identify and resolve vulnerabilities responsibly.

    1. Commitment & Philosophy

    MyDataNest, operated by NWD Production Co., Ltd., is committed to building a secure, robust, and resilient SaaS platform. We recognize the crucial role that independent security researchers play in keeping the internet safe, and we treat every security report with diligence, transparency, and seriousness.

    2. Scope

    This policy applies exclusively to digital assets and systems directly owned and maintained by MyDataNest: - In-Scope Assets: • Primary web application: *.mydatanest.app • Public APIs and MyDataNest backend endpoints • Authentication flows and session management - Out-of-Scope Assets & Testing Methods: • Third-party services and infrastructure (CloudAccess hosting infrastructure, Stripe payment gateway, third-party LLM inference providers) • Denial of Service (DoS / DDoS) attacks • High-volume automated brute-force attacks or API spamming • Social engineering, phishing, smishing, or physical coercion against our staff, contractors, or customers • Vulnerabilities requiring physical access to end-user devices

    3. Rules of Engagement & Safe Harbor

    If you conduct your security research in good faith and adhere strictly to the guidelines below, MyDataNest will consider your research authorized and will not initiate legal action against you: - Act in good faith and comply with all applicable local and international laws. - Do not access, modify, delete, or exfiltrate real customer or company data beyond what is strictly needed for a minimal Proof of Concept (PoC). - Minimize disruption and avoid degrading the availability or performance of our systems and services. - Follow Coordinated Vulnerability Disclosure: do not disclose details of the vulnerability publicly or to third parties until we have had reasonable time to fix and verify the issue. - Immediately notify us if you inadvertently gain access to private personal data or confidential customer information during your research.

    4. How to Report a Vulnerability

    Please send your detailed security report to: Email: info@mydatanest.app Subject: [Security Report] - Brief description of the vulnerability To help us triage and resolve the issue quickly, please include: - A clear explanation of the vulnerability and its potential impact. - Targeted URLs, parameters, endpoints, or components. - Step-by-step instructions to reproduce the issue (curl requests, minimal payload, screenshots, or PoC video). - Remediation suggestions or references, if available.

    5. Our Commitments & Response SLA

    When you submit a report following these guidelines, we commit to: - Acknowledge receipt of your report within 48 business hours. - Investigate, validate, and triage the vulnerability within 5 business days. - Keep you updated on the remediation timeline and progress. - Prioritize remediation according to severity (CVSS score) and deploy fixes promptly.

    6. Recognition & Hall of Fame

    We deeply appreciate the contributions of researchers who help us protect MyDataNest: - Upon request, we will gladly acknowledge your name, handle, or organization in our Security Acknowledgments once the vulnerability has been remediated. - Note: MyDataNest does not currently operate a paid monetary bug bounty program, but we provide full public credit and formal recognition for valid responsible disclosures.