Vulnerability Disclosure Policy

Our Commitment 

Nebula IT Services Ltd takes the security of our systems, services, and customer data seriously. 

We welcome reports from security researchers, customers, partners, and members of the public who believe they have identified a security vulnerability in any Nebula-owned system, application, service, or website. 

We are committed to investigating reports responsibly, responding in a timely manner, and taking appropriate action to remediate verified security vulnerabilities. 

How to Report a Vulnerability 

Please report vulnerabilities by email to: 

Email: help@nebula.support 

To help us investigate your report efficiently, please include: 

  • A description of the vulnerability 
  • The affected system, application, service, or website 
  • Steps required to reproduce the issue 
  • The potential impact of the vulnerability 
  • Screenshots, logs, or other supporting evidence where available 
  • Any relevant CVE references or vendor advisories 

Reports submitted in good faith will be reviewed and handled confidentially. 

What You Can Expect From Us 

When you submit a vulnerability report, Nebula aims to: 

Activity Target Time 
Acknowledge receipt Within 5 business days 
Initial assessment Within 10 business days 
Triage and assignment Within 15 business days 
Ongoing updates Every 10 business days until closure 

Where possible, we will keep reporters informed about the progress of investigations and remediation activities. 

These timescales are targets rather than guarantees and may vary depending on complexity and operational priorities. 

Responsible Disclosure Guidelines 

When testing or reporting vulnerabilities, we ask that you: 

Do 

  • Act in good faith. 
  • Make every effort to avoid privacy violations, service disruption, or data destruction. 
  • Report vulnerabilities promptly after discovery. 
  • Give Nebula reasonable time to investigate and remediate issues before any public disclosure. 
  • Provide sufficient information to enable us to reproduce and verify the issue. 

Do Not 

  • Access, modify, download, copy, or delete data that does not belong to you. 
  • Exploit a vulnerability beyond what is necessary to demonstrate its existence. 
  • Conduct denial-of-service attacks. 
  • Introduce malware or malicious code. 
  • Attempt social engineering attacks against customers, employees, or suppliers. 
  • Attempt physical intrusion into Nebula facilities. 
  • Disclose vulnerabilities publicly before Nebula has had the opportunity to investigate and resolve the issue. 

Scope 

This policy applies to vulnerabilities affecting systems and services owned and operated by Nebula IT Services Ltd, including: 

  • Public websites 
  • Customer portals 
  • Cloud-hosted services 
  • Internet-facing applications 
  • Supporting infrastructure 

The following are generally considered out of scope: 

  • Denial of Service (DoS/DDoS) attacks 
  • Spam or social engineering campaigns 
  • Vulnerabilities requiring physical access 
  • Automated vulnerability scan reports without evidence of a genuine security issue 
  • Issues involving unsupported browsers or end-of-life software 

Safe Harbour 

Nebula will not pursue legal action against individuals who: 

  • Act in good faith. 
  • Follow this policy. 
  • Avoid privacy violations, service disruption, and data destruction. 
  • Promptly report identified vulnerabilities. 

This safe harbour applies only to activities conducted in accordance with this policy. 

Confidentiality 

Information relating to reported vulnerabilities will be treated as confidential and shared only with individuals who require access for investigation, remediation, compliance, legal, or regulatory purposes. 

Public Disclosure 

Nebula believes in responsible vulnerability disclosure. 

We request that researchers do not publicly disclose vulnerabilities until: 

  1. Nebula has confirmed the issue; 
  1. Reasonable remediation efforts have been completed; and 
  1. Both parties have agreed upon an appropriate disclosure timeline. 

Contact Information 

Security reports should be submitted to: 

Email: help@nebula.support 

For urgent security matters affecting service availability or involving active exploitation, please contact: 

Telephone: 01454 534009