Security Policy

NEXUS - Manufacturing Intelligence Platform

NEXUS is a manufacturing intelligence platform used by UK engineering firms. If you have found a security vulnerability in it, this document tells you how to report it and what will happen next.

1. Why this exists - the Computer Misuse Act

This is the part a template copied from a US company will not tell you.

The Computer Misuse Act 1990 has no public-interest defence and no researcher safe harbour. Under s.1, causing a computer to perform a function with intent to secure unauthorised access is an offence, regardless of motive. A UK researcher who probes a system without permission commits that offence even if they intended only to report what they found and did no harm.

The practical consequence is not theoretical: without published authorisation, a researcher who spots something has two bad options - stay silent, or report it and hope. Many choose silence, and some choose disclosure elsewhere. A vulnerability disclosure policy is how an organisation removes that dilemma, by granting the permission that makes the testing authorised in the first place.

That is why section 3 is written as authorisation rather than as a request.

2. Scope

In scope

Out of scope

3. Authorisation

If you act within section 2 and follow section 4, we authorise your testing of NEXUS for the purpose of finding and reporting security vulnerabilities. We will not pursue or support any civil or criminal action against you for that work, and we will not ask you to sign a non-disclosure agreement as a condition of reporting.

This authorisation covers systems we operate. It cannot cover a customer's own deployment - NEXUS is single-tenant, each customer has their own instance, and only that customer can authorise testing of theirs.

4. How to report

Email security@nexusmes.co.uk. Please include:

Please do not access, modify or download other people's data. If you reach a point where you could, stop - the fact that you got there is the finding, and demonstrating it further does not strengthen the report.

5. What to expect

NEXUS is built and maintained by one person, so these are what can honestly be met rather than what sounds impressive:

StageTarget
Acknowledgement that your report arrived5 working days
Initial assessment and a severity view10 working days
Fix, or a plan with dates if it is not quickAgreed with you
Confirmation once it is resolvedSame day as the fix

If a fix will take a while, you will be told why rather than left waiting. We will credit you by name in the release notes if you want that, and not if you do not.

There is no bug bounty - no payment is offered. Saying so plainly is fairer than leaving it ambiguous.

6. Personal data

If a vulnerability has exposed personal data, that is a personal data breach under UK GDPR and carries a 72-hour notification duty to the ICO from the point of awareness, plus notification to affected individuals where the risk is high. Say so explicitly in your report if you believe personal data was reachable - it changes the clock we are working to, not just the priority.

Our data retention schedule and processing detail are available to customers and prospective customers on request from the address in section 8.

7. Standards this follows

British and UK-applicable:

PSTI Act 2022 does not apply. The Product Security and Telecommunications Infrastructure regime mandates disclosure policies for consumer connectable products. NEXUS is business-to-business software and is out of its scope. Noted here so it is visibly considered rather than overlooked.

For reporting matters onward: the NCSC for national-level incidents, Action Fraud for criminal activity, and the ICO for personal data breaches.

8. Contact

All three components of the NCSC toolkit are in place:

There is no PGP key. If your report needs encryption before you will send it, say so at the address above and we will arrange a channel.

9. Review

Annually, and whenever the scope in section 2 changes - a new portal, a public API surface, or the first customer-operated deployment. The Expires field in security.txt carries the same anniversary, so a lapsed review shows up as an invalid file rather than as nothing at all.