Skip to main content
NIJA.

Reporting a security flaw

If you have found a security flaw in Nija, tell us. This page is the published way to reach the people who can fix it, and it is for anyone who has found something, whether or not you hold a Nija account.

How to report

Nija has not yet published a reporting address, so there is nothing on this page to send a report to.

While you are looking, use only your own account and your own data. Do not read, change or delete anyone else's information, and do not degrade the service for other people.

What is in scope

The Nija platform and the surfaces Nija operates: the website and developer console, the chat application, the public API, and the services behind them.

What is not in scope

The upstream model providers Nija routes to, which run their own disclosure programmes. Denial-of-service and load testing. Social engineering of Nija people, partners or customers. Physical attacks on people or premises.

Legal authorisation

Nija has not published a statement about legal authorisation for security research. Nothing on this page gives you permission to test, and no undertaking is made here about legal action.

What happens next

Nija has not published a target time for acknowledging or resolving a report.

The machine-readable version

Nija is not publishing a security.txt file yet, so there is no machine-readable version of this policy to fetch.

Security · Nija