Security
Security Policy
We take the security of Nelieo NSP and our users' data seriously. This page describes how to responsibly report security vulnerabilities to us.
Reporting a Vulnerability
If you believe you've found a security vulnerability in any Nelieo product or infrastructure, please report it to us by emailing:
security@nelieo.comPlease include as much detail as possible: steps to reproduce, potential impact, and any proof-of-concept code. We read every report and will respond within 48 hours.
What to Include in Your Report
01The URL, endpoint, or component affected
02A description of the vulnerability and its potential impact
03Steps to reproduce the issue
04Any proof-of-concept code or screenshots
05Your contact information for follow-up questions
Our Commitments to You
✓We will acknowledge your report within 48 hours
✓We will not take legal action against you for good-faith security research
✓We will keep you informed of our progress in fixing the issue
✓We will credit you in our security acknowledgements (if you wish)
✓We will not share your personal information without your consent
Out of Scope
✗Denial of Service (DoS/DDoS) attacks
✗Social engineering or phishing attacks against Nelieo employees
✗Physical security attacks
✗Vulnerabilities in third-party services (Clerk, Vercel, Neon)
✗Reports generated by automated scanners without manual verification
Our Security Practices
AuthenticationClerk (SOC 2 Type II certified)
Data at RestAES-256 encryption via Neon Postgres
TransportTLS 1.3 enforced everywhere
API Keys90-day expiry, stored in private metadata
Rate Limiting10 req/min per IP on all auth endpoints
Audit LogsImmutable event log for all key operations