Reporting a security issue to Nyfty.ai
Nyfty.ai welcomes reports of security vulnerabilities in the services we operate. If you have
found something, we would rather hear about it from you than from a customer. This page tells
you what we cover, how to reach us, what we will do, and what we will not do.
1. Scope
In scope — services Nyfty operates:
console.nyfty.ai — the customer web console
devices.nyfty.ai, kiosk.nyfty.ai, mytasks.nyfty.ai
l.nyfty.ai — our short-link hostname, the links SMS and email recipients open
nyfty.ai and www.nyfty.ai — our marketing site, which also serves this page. The content is
ours; the platform serving it is Cloudflare’s, so platform-level findings there belong to
Cloudflare rather than to us
static.nyfty.ai — our static asset host, on the same basis as the marketing site above
Short links also resolve at the /l/<code> path on the application hostnames above — for example
https://console.nyfty.ai/l/<code>. That path is in scope wherever the hostname it sits on is in
scope.
These are live production services used by people on active construction sites. Please test
conservatively (see §5).
Out of scope:
- Third-party services we use but do not operate — our cloud platform and productivity suite, our
source-hosting and DNS providers, and the payment, messaging, email, CRM, analytics, collaboration
and construction-platform vendors we integrate with. Report issues in those products to the vendor
who runs them. One exception, and it is in scope: if a Nyfty misconfiguration of a
third-party service exposes Nyfty or customer data, we want to hear about it.
- Denial of service of any kind — volumetric, application-layer or resource-exhaustion — and any
test that degrades service for other users.
- Social engineering of Nyfty staff, customers, suppliers or contractors, including phishing,
pretexting and any attempt to obtain credentials from a person.
- Physical attacks against premises, people or devices.
- High-volume automated activity — bulk scanning, fuzzing, brute-force or credential-stuffing
traffic against our production hosts, and automated submission of forms. Scanner output alone,
without a demonstrated impact, is not a report we can act on.
Configuration observations with no demonstrated security impact — the absence of an optional HTTP
response header, for example — are welcome as informational notes. We will read them, but we do not
treat them as vulnerabilities and we will not report progress on them.
2. How to report
Email hello@nyfty.ai.
If you need to send material you would rather not put in plain email, say so in your first message
and we will agree a channel with you. We do not currently publish an encryption key.
3. What to include
The more of this you can give us, the faster we can act:
- the affected host or URL, and the date and time of your testing;
- what you found, and what an attacker could do with it;
- steps to reproduce, and any proof-of-concept code, request or screenshot;
- any account, IP address or user agent you used, so we can find your activity in our logs;
- whether you accessed, altered or retained any data that was not yours; and
- whether you intend to publish, and when.
Please write in English.
4. What happens next
- We will acknowledge your report within ten business days, provided it is in scope under §1 and
contains the information asked for in §3. We expect to reply sooner; ten business days is what we
are confident of meeting through holidays and travel, as a three-person company with no overnight
cover and no triage rota.
- We do not undertake to reply to every message. Reports that fall outside the scope in §1, that
consist of automated scanner output with no demonstrated vulnerability, or that are not made in
good faith may receive no response. Whether a report meets these conditions is Nyfty’s
determination.
- Reports will be escalated to the Chief Technology Officer and the Chief Executive Officer and
handled under Nyfty’s Incident Response Plan. Nyfty is a three-person company: there is no
dedicated security function and no triage rota, and we would rather tell you that than imply one
exists.
- We will tell you what we intend to do, and we will tell you when it is done. We do not commit
to a fixed remediation deadline for externally reported issues, and we do not publish a severity
model for them. We will give you our assessment and our intended timing case by case.
- Your report may already be known to us. Some issues are recorded in an internal remediation
register with an owner and a target date. If yours is one of them we will say so, and we will still
credit you.
- Credit. If you would like to be named once an issue is resolved, tell us and we will name you.
If you would rather not be, we will not.
5. Rules for good-faith research
Stay inside these and you stay inside our safe harbour:
- Use your own test accounts and your own data. Do not access, modify, delete or retain data
belonging to anyone else. If you encounter someone else’s data, stop, do not save it, and tell us.
- Stop as soon as you have confirmed a vulnerability. Do not pivot, escalate or persist.
- Do not degrade, interrupt or overload our services, and do not test in a way that reaches people
working on a site.
- Do not use the finding for anything other than demonstrating it to us.
- Give us a reasonable opportunity to fix the issue before you publish. We will not name a fixed
number of days we cannot guarantee to meet — talk to us and we will agree a date together.
6. Safe harbour
If you follow this policy in good faith, Nyfty will not initiate or support legal action against
you in connection with your research, and we will treat your activity as authorised access to our
systems. If a third party brings a claim against you for research that complied with this policy, we
will make it known that your activity was authorised. (This is a statement of fact about
authorisation, not an indemnity and not an undertaking to fund a defence.)
This commitment covers only the systems listed as in scope in §1. It cannot and does not authorise
you to test systems operated by anyone else, and it does not waive any third party’s rights. Nothing
here removes your obligations under applicable law.
7. No bug bounty
Nyfty does not operate a bug bounty programme and does not pay for vulnerability reports. There
is no reward, no swag and no payment, at any severity. We say this plainly and up front so that no
one spends time on the expectation of one. What we offer is an acknowledgement within ten business
days, an honest account of what we are doing about it, and credit if you want it.