Skip to main content

Security policy

Nerve handles transactional traffic, API credentials, and recipient contact data for every workspace on the platform. We welcome reports from independent researchers and take them seriously.

Reporting a vulnerability

Do not open a public GitHub issue, pull request, or discussion for a security problem.

Email security@nervly.io with a description of the issue and the steps to reproduce it. If you prefer encrypted email, ask for our PGP key in your first message and we will reply with it.

Please include, where you can:

  • A clear description of the vulnerability and its impact.
  • The affected component or URL (for example api.nervly.io or app.nervly.io).
  • Reproduction steps or a proof-of-concept.
  • Any conditions required to exploit it.
  • Whether you have already disclosed it elsewhere.

If you want to verify a finding against your own workspace, use a Test mode API key (nerve_sk_test_...) rather than sending to real recipients.

Our commitments

StageTarget
Acknowledgement of your reportWithin 2 business days
Initial triage and severity assessmentWithin 5 business days
Status update cadence while a fix is in progressEvery 7 calendar days
Fix or documented mitigation for critical issuesAs fast as severity warrants; we agree a disclosure date with you

We will keep you informed, tell you if we cannot reproduce the issue, and credit you in the fix's changelog entry unless you ask us not to.

Coordinated disclosure and safe harbour

We follow coordinated disclosure. We will not take legal action against researchers who act in good faith — who avoid privacy violations and service degradation, only test accounts and workspaces they own or have permission to test, do not exfiltrate or pivot across tenant data, and report promptly without exploiting a finding beyond what is needed to demonstrate it.

Scope

In scope: the ingest gateway (api.nervly.io), the developer dashboard (app.nervly.io), the management API (console.nervly.io), this documentation portal and the marketing site, and platform behaviours including cross-tenant isolation, authentication and session handling, credential storage, billing integrity, and injection into outbound messages.

Out of scope: findings that need a compromised device or physical access; volumetric denial-of-service without a prior written agreement; scanner output with no demonstrated impact; missing best-practice hardening with no exploitable consequence; social engineering; and the platforms of our upstream providers (Termii, SendGrid, Postmark, Paystack, and similar), which should be reported to the provider directly.

Supported versions

Nerve is a continuously updated service; there are no self-hosted versions to patch. The latest release of each component is the supported version, and security fixes are recorded in that component's changelog.