Reporting a security flaw
If you have found a security flaw in Nija, tell us. This page is the published way to reach the people who can fix it, and it is for anyone who has found something, whether or not you hold a Nija account.
How to report
Nija has not yet published a reporting address, so there is nothing on this page to send a report to.
While you are looking, use only your own account and your own data. Do not read, change or delete anyone else's information, and do not degrade the service for other people.
What is in scope
The Nija platform and the surfaces Nija operates: the website and developer console, the chat application, the public API, and the services behind them.
What is not in scope
The upstream model providers Nija routes to, which run their own disclosure programmes. Denial-of-service and load testing. Social engineering of Nija people, partners or customers. Physical attacks on people or premises.
Legal authorisation
Nija has not published a statement about legal authorisation for security research. Nothing on this page gives you permission to test, and no undertaking is made here about legal action.
What happens next
Nija has not published a target time for acknowledging or resolving a report.
The machine-readable version
Nija is not publishing a security.txt file yet, so there is no machine-readable version of this policy to fetch.