Responsible Disclosure Program
Status: Active
Overview
LNC Nexus welcomes private reports from security researchers, customers, and partners. This public page intentionally avoids implementation details, system identifiers, and reproduction examples that could help someone attack the service.
Report Privately
- Use a GitHub Security Advisory for a private report.
- For an alternate channel, contact the security team at sshaffer@woclegalnurse.net.
- Do not include credentials, secrets, personal health information, or exploit payloads in an initial message.
Please provide only the minimum information needed to validate the issue: a concise description, affected product area, impact, safe reproduction guidance, and the version or deployment context if known. Share sensitive evidence only through an agreed private channel.
Researcher Safety Rules
Researchers must:
- Test only systems and accounts they own or are explicitly authorized to assess.
- Use synthetic or non-sensitive data.
- Stop testing and report immediately if data exposure or service impact is possible.
- Avoid persistence, privilege escalation, data access, service disruption, social engineering, and physical testing.
- Allow time for validation, remediation, and coordinated communication before public disclosure.
We will not pursue legal action against good-faith researchers who follow this policy and avoid accessing or changing data that is not theirs.
Response Process
Reports are acknowledged, validated, risk-ranked, remediated, and verified through a coordinated process. We will communicate material status changes and coordinate public disclosure when appropriate. Response timing depends on severity, reproducibility, and operational risk; target dates are not guarantees.
Scope
Reports about LNC Nexus application security, authorization, data protection, integrations, or deployment guidance are welcome. Third-party products, social engineering, denial-of-service activity, and issues without a security impact should be reported to the relevant owner or service provider.
Recognition
With permission, we may recognize researchers in release notes or a security acknowledgments list. Recognition is discretionary and is not a promise of payment or bounty.
Contact
Security Team: sshaffer@woclegalnurse.net Private Advisory Channel: GitHub Security Advisories
Revision History
| Version | Status |
|---|---|
| 1.1 | Public-safe disclosure guidance |