Skip to main content

Legal

Security Policy

If you believe you have found a vulnerability in Nisatsu, please report it privately rather than filing a public issue.

Reporting

  • Email contact@nisatsu.com.
  • Include: affected URL or file, reproduction steps, expected vs. observed behavior, and the impact you believe it has.
  • Please do not test on accounts you do not own, and do not exfiltrate more data than the minimum needed to demonstrate the issue.

We acknowledge valid reports within 3 business days and aim to ship a fix within 30 days for high-severity findings. We will credit reporters who want public acknowledgment once a fix has shipped.

Scope

In scope:

  • nisatsu.com and subdomains
  • nisatsu.app and subdomains
  • The Nisatsu mobile app (iOS / Android)
  • The Nisatsu HTTP API served from the web app

Out of scope:

  • Rate-limit bypasses on unauthenticated endpoints that do not grant additional privilege or cost
  • Social-engineering of Nisatsu staff or users
  • Physical attacks
  • Findings against third-party subprocessors (report those directly to the provider)

Safe harbor

We will not pursue legal action against researchers who follow this policy in good faith. Thank you for helping keep Nisatsu users safe.

More

Machine-readable contacts are published at /.well-known/security.txt. See our Privacy Policy for how we handle your data.

Security Policy · Nisatsu