Bug Bounty Program

Found a security flaw in the NEXO website or API? Report it to the address below, test only with your own accounts and do not publish before the fix. Good-faith research within these rules is authorized.

security@nexo.wiki.br

In scope

This version of the program covers:

  • The nexo.wiki.br website. Public pages, the signed-in area, the web game and the routes under nexo.wiki.br/api.
  • The NEXO API on Supabase. REST, RPC functions, Auth and Storage of the project the website calls (the address shows up in the website's own requests). What counts is NEXO's configuration: permissions, row-level policies and functions. Flaws in the Supabase platform itself go straight to Supabase.

Examples of what we care about: reading or changing another account's data, getting Pro or Max without paying, becoming an administrator, bypassing the game logic on the server, stored XSS, SQL injection and exposed secret keys.

Out of scope

  • The iOS app and the admin panel.
  • Third-party services such as Vercel, Supabase (the platform), Stripe, RevenueCat, Google, Apple and the email provider. Report to them directly.
  • Denial of service, load testing, spam and brute force.
  • Social engineering, phishing and physical access.
  • Scanner output without proof of impact, software versions without a demonstrated exploit, and missing headers, SPF or DMARC without concrete impact.
  • Errors in the medical content of a case. That is not a security flaw: use the contact page.

Testing rules

  • Use only your own accounts. To test cross-account access, create two accounts of your own.
  • Never read, change, delete or download other people's data. If you come across someone else's data, stop, keep no copy and report it.
  • Show the impact with the minimum needed: one record is enough, not a whole table.
  • Keep the volume low, at most 5 requests per second, with no mass scanning.
  • Do not keep access, install anything on the server or use the flaw beyond what proves the problem.
  • Do not test payments with someone else's card or touch other players' rankings, points or achievements.
  • Keep the flaw confidential until it is fixed.

How to report

Write to security@nexo.wiki.br with:

  • what you found and its impact;
  • the steps to reproduce it;
  • requests and responses, screenshots or video;
  • the email addresses of the test accounts you used;
  • how you want to be credited (name or handle, link and country) or whether you prefer to stay anonymous.

Do not send other people's personal data. We reply in Portuguese, English, Spanish, French, German and Russian. If the report involves sensitive data, send only the minimum and ask us to set up a channel for it.

What to expect

  • Receipt. Confirmation within 3 business days.
  • Assessment. Within 14 days we tell you whether the flaw is valid, how severe it is and whether it was already known.
  • Follow-up. An update at least every 30 days until the report is closed.
  • Fix. The timeline depends on severity. We let you know when it is fixed and you can test again to confirm.
  • Duplicates. When more than one person reports the same flaw, the first valid report counts.

Coordinated disclosure: please do not publish anything before the fix. If the fix takes longer than 90 days from confirmation, we agree on a date together.

Safe harbor

  • Research carried out in good faith and within this policy is treated as authorized.
  • NEXO will not start or support legal action against you for that research.
  • If someone takes action against you for research within the policy, NEXO will state that it was authorized.
  • This does not apply to anyone who breaks the rules, deliberately reaches other people's data or demands payment under threat of disclosing the flaw. It does not authorize testing third-party services either.
  • If you are unsure whether something is in scope, ask by email first.

Recognition

  • Hall of Fame. Your name or handle, link and country on this page, if you want.
  • NEXO Max. Months of NEXO's most complete plan on your account, according to the impact.
  • Payment. Flaws with significant impact may receive a payment proportional to the impact, agreed with the team case by case after proof. Payment is processed by HackerOne, which asks the researcher for a tax form and identity verification before transferring the money. There is no price table, and the decision to pay and the amount are NEXO's.
  • Returning researchers. Researchers with previously confirmed reports get a bonus on top of the Max months and the payment.

Recognition applies to the first valid report of each flaw, within scope and the rules. Payment depends on tax details and on the law allowing the transfer to your country.

Hall of Fame

No names yet. The first valid report starts the list.