# NEXUS - Manufacturing Intelligence Platform # Vulnerability disclosure contact, per RFC 9116. # # Testing within the scope of the policy below is AUTHORISED. That authorisation # is the point of this file, not a formality: the Computer Misuse Act 1990 has no # public-interest defence and no researcher safe harbour, so in the UK a # researcher without published permission commits an offence by finding a bug at # all. The policy grants that permission explicitly. # # The Policy URL below ends in .html deliberately. It is an exact path served by # Vercel's filesystem handler, so it cannot depend on extension inference or a # directory index. An earlier draft pointed at an extensionless /security-policy, # which has no React route and no file - it fell through to the SPA rewrite and # rendered a blank page. A disclosure policy that cannot be opened is worse than # none, so this URL is pinned to a file that demonstrably exists. Contact: mailto:security@nexusmes.co.uk Expires: 2027-07-26T00:00:00.000Z Preferred-Languages: en Canonical: https://nexusmes.co.uk/.well-known/security.txt Policy: https://nexusmes.co.uk/security-policy.html # Expires is MANDATORY under RFC 9116 and an expired file is treated as invalid - # it does not degrade, it stops counting. The date above is the same anniversary # as the annual policy review, so the review is what renews it. Review BEFORE # this date, not on it. # # There is no bug bounty and no PGP key. Both are stated plainly rather than # omitted, because absence reads as oversight and a researcher deserves to know # before spending their time.