Security contact
Report vulnerabilities responsibly.
We welcome good-faith security research that helps protect Nexus users and infrastructure.
How to report
Email security@lumiversenexus.com with a clear description, affected component, reproduction steps and impact. Do not send active malware or large archives until requested.
Good-faith guidelines
- Avoid accessing, modifying or deleting data that is not your own.
- Do not disrupt production services, run denial-of-service tests or publish sensitive details before coordinated remediation.
- Use the minimum testing necessary to demonstrate the issue.
- Allow reasonable time for investigation and remediation.
Scope
Lumiverse Nexus products and services controlled by Lumiverse Dynamic are in scope. Third-party hosting, WordPress core, unrelated plugins and customer websites should be reported to their respective maintainers unless the issue is caused by Nexus.
Response
We aim to acknowledge credible reports promptly. Timelines vary with severity, reproducibility and coordination requirements. This page is not a bug-bounty promise.