Security

Security Policy

We take the security of Nelieo NSP and our users' data seriously. This page describes how to responsibly report security vulnerabilities to us.

Reporting a Vulnerability

If you believe you've found a security vulnerability in any Nelieo product or infrastructure, please report it to us by emailing:

security@nelieo.com

Please include as much detail as possible: steps to reproduce, potential impact, and any proof-of-concept code. We read every report and will respond within 48 hours.

What to Include in Your Report

01The URL, endpoint, or component affected
02A description of the vulnerability and its potential impact
03Steps to reproduce the issue
04Any proof-of-concept code or screenshots
05Your contact information for follow-up questions

Our Commitments to You

We will acknowledge your report within 48 hours
We will not take legal action against you for good-faith security research
We will keep you informed of our progress in fixing the issue
We will credit you in our security acknowledgements (if you wish)
We will not share your personal information without your consent

Out of Scope

Denial of Service (DoS/DDoS) attacks
Social engineering or phishing attacks against Nelieo employees
Physical security attacks
Vulnerabilities in third-party services (Clerk, Vercel, Neon)
Reports generated by automated scanners without manual verification

Our Security Practices

AuthenticationClerk (SOC 2 Type II certified)
Data at RestAES-256 encryption via Neon Postgres
TransportTLS 1.3 enforced everywhere
API Keys90-day expiry, stored in private metadata
Rate Limiting10 req/min per IP on all auth endpoints
Audit LogsImmutable event log for all key operations