# Security

Version 1.1 · effective from 2026-08-16

## 1. Scope

niblo.app security covers the application, Accounts, user data, software delivery, infrastructure and incident response. This public policy explains controls and responsible disclosure without exposing attack-enabling configuration.

## 2. Defence model

Layered controls include TLS, secure password storage, least-privilege role-based access, environment separation, session and form protection, server-side validation, backups, monitoring, administrative audit trails and dependency updates.

Production administration is restricted, key-authenticated, filtered and audited. Releases pass integrity verification, tests, staging, pre-change backup and health gates. Secrets must not enter source control or public logs.

## 3. Data and resilience

Server-side authorisation protects User and module boundaries. Encrypted rotating backups are periodically validated by restore drills. Monitoring covers application health, background jobs, scheduling, capacity, certificates and backups. Backups support disaster recovery and are not a personal archive.

## 4. Account security

Use a unique password and secure the linked mailbox. Support never asks for a password, one-time code or recovery secret in a message. If compromise is suspected, secure email first, recover the Account, terminate unknown sessions and contact contact@niblo.app.

## 5. Responsible disclosure

Send suspected vulnerabilities confidentially to contact@niblo.app with subject “Security vulnerability”. Include impact, affected URL, minimal reproduction, browser version, sanitised evidence and contact preference.

Do not publish details before remediation and a reasonable coordinated disclosure date. We aim to acknowledge within three business days, triage the issue and provide meaningful updates. No financial reward is guaranteed; recognition requires the reporter’s consent.

## 6. Permitted testing scope

Without prior written authorisation, test only your own Account and data, manually, non-destructively and at low volume. Stop after confirming the issue and report the minimum proof.

Do not access another person’s data, modify or delete data, maintain persistence, phish, perform denial-of-service or mass scanning, crack credentials, automate account creation, test third-party providers, distribute malware, attempt physical access or publish personal data.

## 7. Safe harbour

Where a researcher acts in good faith, follows this Policy, avoids harm and respects privacy, the Operator will not initiate legal action solely because of that research. This does not authorise unlawful conduct or testing third-party systems. When uncertain, describe the proposed test to contact@niblo.app and wait for written approval.

## 8. Severity and triage

Priority reflects impact, exploitability, number of affected people and data exposure. System compromise, mass disclosure and authentication bypass take priority over local-only or cosmetic issues. Duplicates, no-impact reports and missing headers without an exploitation path may be informational.

## 9. Incident response

Response includes detection, logging, triage, containment, eradication, trusted recovery, post-change monitoring and review. Evidence is preserved only as needed. Personal-data breaches are assessed for supervisory notification and affected people are informed without undue delay where high risk is likely, subject to legal exceptions.

## 10. Updates and dependencies

Dependencies are checked during build and update processes. Security fixes may ship outside the normal schedule. Unsupported, unnecessary or unacceptably risky components can be disabled immediately.

## 11. Messages and encryption

Message transport uses TLS. Conversation trust verification requires participants to compare trust information. Interface indicators cannot protect against phishing, a compromised endpoint or a recipient copying content.

## 12. Limitations and contact

No system is risk-free. Public Status does not disclose infrastructure details and is not a security certification. Vulnerabilities and compromises: contact@niblo.app; ordinary Account access: contact@niblo.app; personal-data rights: contact@niblo.app.

