Security Vulnerability Disclosure & Bug Bounty Policy
If you’ve found a security vulnerability on Nursevests, we encourage you to contact us immediately. We review legitimate security reports and aim to address valid issues as quickly as reasonably possible.
Before reporting a vulnerability, please review this document, including our fundamentals, bounty program, reward guidelines, and non-reportable issues.
Fundamentals
If you follow the principles below when reporting a security issue to Nursevests, we will not initiate legal action or enforcement investigations against you in response to your report, provided your activities remain within the boundaries described below.
We ask that you:
- Give us reasonable time to review and address the issue before disclosing it publicly or sharing it with others.
- Do not interact with or access private accounts without the account owner’s consent.
- Make a good-faith effort to avoid privacy violations, service disruptions, or data destruction.
- Do not exploit the vulnerability beyond what is reasonably necessary to demonstrate the issue, and do not access, modify, or exfiltrate sensitive data.
- Comply with all applicable laws and regulations.
Bounty Program
We recognize and reward security researchers who help protect Nursevests by responsibly reporting vulnerabilities. Bounties may be awarded at Nursevests’ discretion based on risk, impact, exploitability, and report quality.
To potentially qualify for a bounty, you must:
- Follow the fundamentals listed above.
- Report a valid security vulnerability that poses a meaningful risk to privacy or security.
- Submit your report through the designated security contact channel rather than contacting employees directly.
- Disclose any accidental privacy violations, data exposure, or service disruptions in your report.
- Understand that while we investigate valid reports, priority is based on risk and impact, and a response may take some time.
- Understand that Nursevests reserves the right to publish submitted reports where legally and reasonably appropriate, while taking reasonable steps to protect sensitive information.
Rewards
Rewards are based on the impact and severity of the reported vulnerability. Please provide detailed and reproducible steps in your report. If the issue cannot be reproduced or sufficiently verified, it may not be eligible for a bounty.
- The first valid report of a previously unknown issue may receive the applicable bounty.
- Multiple bugs caused by a single underlying issue may be treated as one report.
- We assess rewards based on impact, exploitability, affected systems, and report quality.
Maximum Reward Amounts by Severity
Critical Severity — Up to $200
Examples may include:
- Remote Code Execution
- Remote Shell or Command Execution
- Vertical Authentication Bypass
- SQL Injection resulting in unauthorized access to targeted data
- Full account takeover or equivalent access
High Severity — Up to $100
Examples may include:
- Lateral Authentication Bypass
- Disclosure of sensitive internal data
- Stored XSS affecting other users
- Local File Inclusion
- Insecure handling of authentication cookies
Medium Severity — Up to $50
Examples may include:
- Logic or business process vulnerabilities
- Insecure Direct Object References (IDOR)
Low Severity — Recognition Only
Examples may include:
- Open Redirects
- Reflected XSS
- Low-sensitivity information disclosure
Contact Information
📍 Address: 3939 E 14th St, Des Moines, IA 50313, USA
✆ Phone: +1 (727) 481-2003
✉ Email: support@nursevests.com