Security policy
Nerve handles transactional traffic, API credentials, and recipient contact data for every workspace on the platform. We welcome reports from independent researchers and take them seriously.
Reporting a vulnerability
Do not open a public GitHub issue, pull request, or discussion for a security problem.
Email security@nervly.io with a description of the issue and the steps to reproduce it. If you prefer encrypted email, ask for our PGP key in your first message and we will reply with it.
Please include, where you can:
- A clear description of the vulnerability and its impact.
- The affected component or URL (for example
api.nervly.ioorapp.nervly.io). - Reproduction steps or a proof-of-concept.
- Any conditions required to exploit it.
- Whether you have already disclosed it elsewhere.
If you want to verify a finding against your own workspace, use a Test mode API key (nerve_sk_test_...) rather than sending to real recipients.
Our commitments
| Stage | Target |
|---|---|
| Acknowledgement of your report | Within 2 business days |
| Initial triage and severity assessment | Within 5 business days |
| Status update cadence while a fix is in progress | Every 7 calendar days |
| Fix or documented mitigation for critical issues | As fast as severity warrants; we agree a disclosure date with you |
We will keep you informed, tell you if we cannot reproduce the issue, and credit you in the fix's changelog entry unless you ask us not to.
Coordinated disclosure and safe harbour
We follow coordinated disclosure. We will not take legal action against researchers who act in good faith — who avoid privacy violations and service degradation, only test accounts and workspaces they own or have permission to test, do not exfiltrate or pivot across tenant data, and report promptly without exploiting a finding beyond what is needed to demonstrate it.
Scope
In scope: the ingest gateway (api.nervly.io), the developer dashboard (app.nervly.io), the management API (console.nervly.io), this documentation portal and the marketing site, and platform behaviours including cross-tenant isolation, authentication and session handling, credential storage, billing integrity, and injection into outbound messages.
Out of scope: findings that need a compromised device or physical access; volumetric denial-of-service without a prior written agreement; scanner output with no demonstrated impact; missing best-practice hardening with no exploitable consequence; social engineering; and the platforms of our upstream providers (Termii, SendGrid, Postmark, Paystack, and similar), which should be reported to the provider directly.
Supported versions
Nerve is a continuously updated service; there are no self-hosted versions to patch. The latest release of each component is the supported version, and security fixes are recorded in that component's changelog.