Vulnerability Disclosure Program

Nexora Security

We take the security of our platform seriously. If you believe you've found a security vulnerability in a Nexora system, we encourage you to report it responsibly under the terms below.

Policy summary

Test only assets listed in scope. Do not access, modify or destroy other users' data beyond what is needed to demonstrate a vulnerability. Use only your own test accounts. Report promptly and keep details private until we have resolved the issue.

Scope

AssetTypeStatus
javohir.com.uz (www)Marketing siteIN SCOPE
app.javohir.com.uzCustomer web appIN SCOPE
api.javohir.com.uzPublic REST APIIN SCOPE
admin.javohir.com.uzAdmin consoleIN SCOPE
staging.javohir.com.uz / dev.javohir.com.uzPre-productionIN SCOPE
legacy.javohir.com.uzLegacy reporting toolIN SCOPE
docs.javohir.com.uz, status.javohir.com.uzDocs / statusIN SCOPE
Any other *.javohir.com.uz subdomain you discoverOwned by NexoraIN SCOPE

Out of scope

Physical attacks, social engineering, phishing of Nexora staff or usersOUT
Denial of Service (DoS/DDoS), volumetric or resource-exhaustion testingOUT
Automated scanning that generates excessive traffic (throttle your tools)OUT
Third-party services & domains that are not *.javohir.com.uzOUT
Reports from automated tools without a demonstrated, reproducible impactOUT
Missing security headers / best-practice suggestions with no exploit pathOUT
The domain registrar, DNS provider, mail provider, or your own VPS hostOUT

Rules of engagement

Severity & rewards (training tiers)

SeverityExamplesReward
CriticalRCE, full auth bypass, SQLi dumping other tenants, admin takeover$$$$
HighIDOR to other tenants' data, privilege escalation, SSRF to internal, stored XSS in app$$$
MediumReflected XSS, sensitive info leak (debug/config), open redirect chained$$
LowVerbose errors, predictable tokens without takeover, CORS without impact$

How to report

Email security@javohir.com.uz with: title, affected asset/URL, severity, step-by-step reproduction, proof-of-concept, and impact. One vulnerability per report.

Safe harbor. Activity conducted consistently with this policy is considered authorized. We will not pursue action against researchers who follow these rules and act in good faith.

Hall of Fame

Researchers who report valid issues are acknowledged here.

← Back to nexora