nyfty.ai nyfty.ai
Products ▾
Safety Agents for GCs Live
AI bots for PTPs, permits, orientations & more
Predictive Safety Analytics Soon
Forecast risk from your incident history
Subcontractor Safety App Soon
AI-guided PTPs and Toolbox Talks for Foremen
Pricing
Company ▾
About
Our mission and team
Blog
Insights on AI safety in construction
Contact
Get in touch with us
Log in
Home › Vulnerability Disclosure

Vulnerability Disclosure Statement

Version 1.0  ·  Effective 11 August 2026  ·  Report a security issue to hello@nyfty.ai  ·  Machine-readable copy at /.well-known/security.txt

Contents

  1. Scope
  2. How to report
  3. What to include
  4. What happens next
  5. Rules for good-faith research
  6. Safe harbour
  7. No bug bounty

Reporting a security issue to Nyfty.ai

Nyfty.ai welcomes reports of security vulnerabilities in the services we operate. If you have found something, we would rather hear about it from you than from a customer. This page tells you what we cover, how to reach us, what we will do, and what we will not do.

1. Scope

In scope — services Nyfty operates:

  • console.nyfty.ai — the customer web console
  • devices.nyfty.ai, kiosk.nyfty.ai, mytasks.nyfty.ai
  • l.nyfty.ai — our short-link hostname, the links SMS and email recipients open
  • nyfty.ai and www.nyfty.ai — our marketing site, which also serves this page. The content is ours; the platform serving it is Cloudflare’s, so platform-level findings there belong to Cloudflare rather than to us
  • static.nyfty.ai — our static asset host, on the same basis as the marketing site above

Short links also resolve at the /l/<code> path on the application hostnames above — for example https://console.nyfty.ai/l/<code>. That path is in scope wherever the hostname it sits on is in scope.

These are live production services used by people on active construction sites. Please test conservatively (see §5).

Out of scope:

  • Third-party services we use but do not operate — our cloud platform and productivity suite, our source-hosting and DNS providers, and the payment, messaging, email, CRM, analytics, collaboration and construction-platform vendors we integrate with. Report issues in those products to the vendor who runs them. One exception, and it is in scope: if a Nyfty misconfiguration of a third-party service exposes Nyfty or customer data, we want to hear about it.
  • Denial of service of any kind — volumetric, application-layer or resource-exhaustion — and any test that degrades service for other users.
  • Social engineering of Nyfty staff, customers, suppliers or contractors, including phishing, pretexting and any attempt to obtain credentials from a person.
  • Physical attacks against premises, people or devices.
  • High-volume automated activity — bulk scanning, fuzzing, brute-force or credential-stuffing traffic against our production hosts, and automated submission of forms. Scanner output alone, without a demonstrated impact, is not a report we can act on.

Configuration observations with no demonstrated security impact — the absence of an optional HTTP response header, for example — are welcome as informational notes. We will read them, but we do not treat them as vulnerabilities and we will not report progress on them.

2. How to report

Email hello@nyfty.ai.

If you need to send material you would rather not put in plain email, say so in your first message and we will agree a channel with you. We do not currently publish an encryption key.

3. What to include

The more of this you can give us, the faster we can act:

  • the affected host or URL, and the date and time of your testing;
  • what you found, and what an attacker could do with it;
  • steps to reproduce, and any proof-of-concept code, request or screenshot;
  • any account, IP address or user agent you used, so we can find your activity in our logs;
  • whether you accessed, altered or retained any data that was not yours; and
  • whether you intend to publish, and when.

Please write in English.

4. What happens next

  • We will acknowledge your report within ten business days, provided it is in scope under §1 and contains the information asked for in §3. We expect to reply sooner; ten business days is what we are confident of meeting through holidays and travel, as a three-person company with no overnight cover and no triage rota.
  • We do not undertake to reply to every message. Reports that fall outside the scope in §1, that consist of automated scanner output with no demonstrated vulnerability, or that are not made in good faith may receive no response. Whether a report meets these conditions is Nyfty’s determination.
  • Reports will be escalated to the Chief Technology Officer and the Chief Executive Officer and handled under Nyfty’s Incident Response Plan. Nyfty is a three-person company: there is no dedicated security function and no triage rota, and we would rather tell you that than imply one exists.
  • We will tell you what we intend to do, and we will tell you when it is done. We do not commit to a fixed remediation deadline for externally reported issues, and we do not publish a severity model for them. We will give you our assessment and our intended timing case by case.
  • Your report may already be known to us. Some issues are recorded in an internal remediation register with an owner and a target date. If yours is one of them we will say so, and we will still credit you.
  • Credit. If you would like to be named once an issue is resolved, tell us and we will name you. If you would rather not be, we will not.

5. Rules for good-faith research

Stay inside these and you stay inside our safe harbour:

  • Use your own test accounts and your own data. Do not access, modify, delete or retain data belonging to anyone else. If you encounter someone else’s data, stop, do not save it, and tell us.
  • Stop as soon as you have confirmed a vulnerability. Do not pivot, escalate or persist.
  • Do not degrade, interrupt or overload our services, and do not test in a way that reaches people working on a site.
  • Do not use the finding for anything other than demonstrating it to us.
  • Give us a reasonable opportunity to fix the issue before you publish. We will not name a fixed number of days we cannot guarantee to meet — talk to us and we will agree a date together.

6. Safe harbour

If you follow this policy in good faith, Nyfty will not initiate or support legal action against you in connection with your research, and we will treat your activity as authorised access to our systems. If a third party brings a claim against you for research that complied with this policy, we will make it known that your activity was authorised. (This is a statement of fact about authorisation, not an indemnity and not an undertaking to fund a defence.)

This commitment covers only the systems listed as in scope in §1. It cannot and does not authorise you to test systems operated by anyone else, and it does not waive any third party’s rights. Nothing here removes your obligations under applicable law.

7. No bug bounty

Nyfty does not operate a bug bounty programme and does not pay for vulnerability reports. There is no reward, no swag and no payment, at any severity. We say this plainly and up front so that no one spends time on the expectation of one. What we offer is an acknowledgement within ten business days, an honest account of what we are doing about it, and credit if you want it.

nyfty.ai

AI-powered safety compliance for construction. Built for Procore & Autodesk.

Products
Safety Agents for GCsPredictive AnalyticsSubcontractor App
Company
AboutPricingContactBlog
Integrations
ProcoreAutodesk Construction Cloud
© 2026 Nyfty.ai, Inc. All rights reserved.A Yakka Labs companyPrivacy Policy · Terms of Use