Trust center
Vulnerability Disclosure Policy
We welcome good-faith reports that help protect NetDefend Academy learners. This policy defines the limited research we authorize, the systems it covers, and how to report a suspected vulnerability without putting people or data at risk.
Last updated: August 11, 2026
Reporting channel
Email netdefendja@gmail.com with the subject “NetDefend Academy security report.” Do not use the general beta-feedback form for secrets, proof-of-concept material, or vulnerability details. Never send passwords, live authentication tokens, recovery codes, or personal data that is not your own.
In scope
- The production service at https://academy.netdefendgroup.com.
- Accounts, content, and data you own or have explicit written authorization to test.
- Security weaknesses that can be demonstrated with the minimum access and data necessary to explain the impact.
Out of scope
- Other NetDefend Group sites, systems, mailboxes, networks, or domains unless they are expressly added to this policy.
- Vercel Preview deployments, third-party providers, and infrastructure not controlled by NetDefend Group.
- Denial-of-service or load testing, social engineering, phishing, physical testing, spam, malware, persistence, destructive testing, automated high-volume scanning, or attempts to bypass another person's account.
- Reports based only on missing best-practice headers, automated scanner output, version banners, self-XSS, or issues without a plausible security impact.
Research rules
- Use the least invasive technique and keep request volume comparable to ordinary manual use.
- Do not access, modify, download, retain, or disclose another person's data. If you encounter it unexpectedly, stop immediately and report what happened without copying the data.
- Do not degrade availability, alter production records, establish persistence, pivot to another system, or exploit a vulnerability beyond the minimum needed to confirm it.
- Give us a reasonable opportunity to investigate and remediate before publishing details. Do not disclose information that would place learners or systems at risk.
- Comply with applicable law and this policy. This is a disclosure programme, not a bug-bounty programme, and it does not promise payment or reward.
Good-faith authorization and safe harbor
Research performed in a good-faith effort to follow this policy will be treated by NetDefend Group as authorized for the Academy systems expressly listed in scope. We will not initiate or recommend legal action solely for accidental, good-faith violations of this policy when you stop, notify us promptly, avoid harm, and cooperate with reasonable remediation requests.
This statement does not authorize activity outside the stated scope, bind third parties, waive rights belonging to others, or permit violations of law. If you are uncertain whether a proposed test is permitted, contact us and wait for written authorization before proceeding.
What to include
- The affected URL or feature and the date and time observed.
- A concise description of the weakness and its realistic impact.
- Minimal, repeatable steps using a test account and redacted evidence where possible.
- Any safety precautions, cleanup performed, and preferred contact information.
What to expect
We aim to acknowledge a complete report within five business days, assess severity, and provide updates when practical. Remediation time depends on impact and complexity, so this target is not a guarantee of resolution by a particular date. We may ask for clarification, coordinate disclosure timing, or involve an affected provider when necessary.
