Vulnerability Disclosure Policy
Our Commitment
Nebula IT Services Ltd takes the security of our systems, services, and customer data seriously.
We welcome reports from security researchers, customers, partners, and members of the public who believe they have identified a security vulnerability in any Nebula-owned system, application, service, or website.
We are committed to investigating reports responsibly, responding in a timely manner, and taking appropriate action to remediate verified security vulnerabilities.
How to Report a Vulnerability
Please report vulnerabilities by email to:
Email: help@nebula.support
To help us investigate your report efficiently, please include:
- A description of the vulnerability
- The affected system, application, service, or website
- Steps required to reproduce the issue
- The potential impact of the vulnerability
- Screenshots, logs, or other supporting evidence where available
- Any relevant CVE references or vendor advisories
Reports submitted in good faith will be reviewed and handled confidentially.
What You Can Expect From Us
When you submit a vulnerability report, Nebula aims to:
| Activity | Target Time |
| Acknowledge receipt | Within 5 business days |
| Initial assessment | Within 10 business days |
| Triage and assignment | Within 15 business days |
| Ongoing updates | Every 10 business days until closure |
Where possible, we will keep reporters informed about the progress of investigations and remediation activities.
These timescales are targets rather than guarantees and may vary depending on complexity and operational priorities.
Responsible Disclosure Guidelines
When testing or reporting vulnerabilities, we ask that you:
Do
- Act in good faith.
- Make every effort to avoid privacy violations, service disruption, or data destruction.
- Report vulnerabilities promptly after discovery.
- Give Nebula reasonable time to investigate and remediate issues before any public disclosure.
- Provide sufficient information to enable us to reproduce and verify the issue.
Do Not
- Access, modify, download, copy, or delete data that does not belong to you.
- Exploit a vulnerability beyond what is necessary to demonstrate its existence.
- Conduct denial-of-service attacks.
- Introduce malware or malicious code.
- Attempt social engineering attacks against customers, employees, or suppliers.
- Attempt physical intrusion into Nebula facilities.
- Disclose vulnerabilities publicly before Nebula has had the opportunity to investigate and resolve the issue.
Scope
This policy applies to vulnerabilities affecting systems and services owned and operated by Nebula IT Services Ltd, including:
- Public websites
- Customer portals
- Cloud-hosted services
- Internet-facing applications
- Supporting infrastructure
The following are generally considered out of scope:
- Denial of Service (DoS/DDoS) attacks
- Spam or social engineering campaigns
- Vulnerabilities requiring physical access
- Automated vulnerability scan reports without evidence of a genuine security issue
- Issues involving unsupported browsers or end-of-life software
Safe Harbour
Nebula will not pursue legal action against individuals who:
- Act in good faith.
- Follow this policy.
- Avoid privacy violations, service disruption, and data destruction.
- Promptly report identified vulnerabilities.
This safe harbour applies only to activities conducted in accordance with this policy.
Confidentiality
Information relating to reported vulnerabilities will be treated as confidential and shared only with individuals who require access for investigation, remediation, compliance, legal, or regulatory purposes.
Public Disclosure
Nebula believes in responsible vulnerability disclosure.
We request that researchers do not publicly disclose vulnerabilities until:
- Nebula has confirmed the issue;
- Reasonable remediation efforts have been completed; and
- Both parties have agreed upon an appropriate disclosure timeline.
Contact Information
Security reports should be submitted to:
Email: help@nebula.support
For urgent security matters affecting service availability or involving active exploitation, please contact:
Telephone: 01454 534009