Vulnerability Disclosure Policy

Nexwift

About Nexwift Saudi AI company Aram contact Nexwift Careers at Nexwift blog
Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Field Value
Document ID NXW-PUB-VULNERABILITY-DISCLOSURE-POLICY
Version 1.0
Issue Date 2026-01-01
Next Review 2027-01-01
Owner Chief Information Security Officer (CISO)
Classification Public

1. Purpose and Introduction

Nexwift welcomes good-faith security research and considers coordinated disclosure an essential part of protecting our customers, their beneficiaries, and the wider ecosystem that relies on the Aram platform. This Vulnerability Disclosure Policy (VDP) sets out how independent researchers, customers, and members of the public can report suspected security vulnerabilities to Nexwift, what commitments Nexwift makes in return, and the boundaries within which such research must be conducted.

This document is public and may be relied on by any researcher acting in accordance with its terms. It applies to text, voice, and video interaction surfaces exposed by the Aram platform, including any recording, transcript, or summary artefacts these surfaces may generate.

2. Scope

2.1 In scope

The following targets are within the scope of this policy:

Category Examples
Nexwift corporate web presence nexwift.com and its public sub-domains
Aram platform components Publicly reachable web dashboards, embeddable chat surfaces, browser voice/video clients, public REST/HTTPS endpoints operated by Nexwift for the Aram platform
Public marketing and trust properties Documentation, trust centre, and status pages published under Nexwift-controlled domains

2.2 Out of scope

The following are expressly excluded from this policy. Testing against out-of-scope targets is not authorised and may expose the researcher to legal liability under applicable law, including the Kingdom of Saudi Arabia's Anti-Cyber Crime Law.

  • Customer-hosted or customer-operated deployments of the Aram platform, except where the customer has provided prior written authorisation naming the researcher and defining the scope.
  • Third-party services and platforms that the Aram platform integrates with, including messaging channel platforms, telephony providers, WebRTC/media infrastructure providers, AI inference providers, mapping providers, error-monitoring providers, and EU-based cloud infrastructure providers. Vulnerabilities in these providers should be reported to the provider directly under their own disclosure programmes.
  • Physical attacks against Nexwift or supplier facilities, personnel, or hardware.
  • Social engineering of Nexwift staff, contractors, customers, beneficiaries, or suppliers (including phishing, vishing, smishing, and pretexting).
  • Denial-of-service testing, volumetric testing, automated brute-force testing, or any test whose primary effect is to degrade availability.
  • Unsolicited bulk email, SMS, or messaging channel traffic ("spam") directed at Nexwift-operated properties.
  • Findings that lack a demonstrated security impact (for example, missing best-practice HTTP headers on informational pages with no exploit path; software-version banners; theoretical issues without a working proof of concept).
  • Findings resulting from testing conducted outside the terms of this policy.

3. Safe Harbour

Nexwift will not initiate or support legal action against a researcher who, in the good-faith opinion of Nexwift, has complied with this policy. Compliance means, at a minimum, that the researcher has:

  1. Acted in good faith to identify and report a suspected vulnerability;
  2. Kept testing strictly within the scope defined in Section 2.1;
  3. Avoided any access to, modification of, or exfiltration of data beyond what is minimally necessary to demonstrate the issue as a proof of concept;
  4. Avoided any action that degrades or is likely to degrade service availability;
  5. Made no attempt to access data belonging to Nexwift customers, their beneficiaries, or any third party;
  6. Given Nexwift a reasonable period to remediate before any public disclosure; and
  7. Complied with all applicable law, including the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL), the Anti-Cyber Crime Law, and any comparable law of the researcher's own jurisdiction.

This safe harbour is limited to actions Nexwift itself may take. It does not, and cannot, bind third parties (including customers, channel providers, or law-enforcement authorities). Where a researcher's activity inadvertently touches a third-party system or a customer environment, the safe harbour does not extend to any claim brought by that third party or customer.

Safe harbour is void where the researcher has engaged in extortion, threats, or conduct materially inconsistent with good-faith research.

4. Prohibited Activity

The following are prohibited under this policy and, if performed, may result in the researcher losing safe-harbour protection and being referred to competent authorities:

  • Exfiltrating, downloading, retaining, or transferring any data beyond the minimum necessary to prove the vulnerability;
  • Any activity that disrupts, degrades, or is intended to disrupt the availability of the Aram platform or of any customer environment (including denial-of-service, resource exhaustion, message flooding, and call flooding on voice or video surfaces);
  • Testing outside the scope defined in Section 2.1, including testing against customer-hosted deployments without written authorisation;
  • Publishing, disclosing, or communicating the details of a vulnerability to any party other than Nexwift before Nexwift has confirmed that the issue has been remediated (or that a coordinated disclosure date has been agreed under Section 7);
  • Using a discovered vulnerability to pivot into further systems, escalate privileges beyond the proof-of-concept level, or maintain persistence;
  • Accessing, viewing, recording, or attempting to intercept beneficiary conversations, call audio, video streams, transcripts, summaries, or any content in which a customer or beneficiary would have a reasonable expectation of privacy;
  • Any activity that violates applicable law.

5. Reporting a Vulnerability

5.1 Where to send

Reports should be sent to:

Channel Address
Primary security channel info@nexwift.com (attn: Chief Information Security Officer)
Personal-data implications Copy to info@nexwift.com (attn: Data Protection Officer)

Reports may be submitted in English or Arabic.

5.2 What to include

To help Nexwift triage and reproduce the issue efficiently, please include, to the extent reasonably known and available at the time of report:

  • A clear description of the suspected vulnerability and the affected component or URL;
  • Step-by-step instructions to reproduce, including any required request payloads;
  • A minimal, non-destructive proof of concept;
  • The impact you believe the issue has;
  • Any redacted evidence (screenshots, HTTP traces) with sensitive material removed;
  • Your name or handle for correspondence and, if you wish to be credited, for recognition (see Section 8).

5.3 Encryption

Researchers who wish to encrypt sensitive reports may request Nexwift's current PGP key by writing to info@nexwift.com (attn: Chief Information Security Officer).

6. Handling of Voice, Video, and Recorded Content

The Aram platform supports text, voice, and video interaction surfaces. Recording of voice or video sessions is an optional feature that is enabled and configured by the customer; where enabled, the customer is responsible for obtaining any consent required from beneficiaries under applicable law.

Researchers must not attempt to access, capture, replay, or transcribe any voice or video session, recording, transcript, or summary belonging to a customer or a beneficiary. Where a vulnerability report necessarily concerns these surfaces (for example, an authorisation flaw affecting a media endpoint), the proof of concept must use only researcher-created test content on researcher-created accounts, must not involve any real beneficiary, and must not persist recordings beyond what is minimally required to demonstrate the issue.

Ownership of customer configurations, knowledge-base content, transcripts, recordings, and summaries rests with the customer; the platform, models, and aggregated operational telemetry rest with Nexwift. Nothing in this policy alters that allocation.

7. Coordinated Disclosure

Nexwift favours coordinated disclosure. On receipt of a valid report, Nexwift will work with the reporter to agree a disclosure timeline that reflects the severity of the issue, the availability of a fix, the effort required by customers to apply any related change, and the risk of parallel independent discovery.

Absent agreement to the contrary, no details of a vulnerability should be disclosed publicly before Nexwift has confirmed remediation (or until the agreed disclosure date, whichever is earlier). Where remediation depends on a third-party provider, the disclosure date may be aligned with that provider's own timeline.

Where a researcher and Nexwift cannot agree a disclosure date, the parties will discuss next steps in good faith. Public disclosure by a researcher of unremediated details, prior to any agreed date, is inconsistent with this policy and withdraws safe-harbour protection under Section 3.

8. Recognition

Nexwift maintains a discretionary hall of fame acknowledging researchers whose reports have led to a material security improvement. Inclusion is at Nexwift's sole discretion, requires the researcher's consent, and may be omitted or delayed where publication would itself create risk.

This policy does not offer a monetary bounty. Nexwift does not, by this policy, commit to any monetary payment for a report, and any recognition granted is a gesture of thanks, not a contractual entitlement.

9. Data Protection

Any personal data submitted in the course of a report is processed by Nexwift as a Data Controller for the purposes of triaging, investigating, and remediating the reported issue and, where the researcher consents, for recognition. Contact details are retained for the duration of the investigation and any related follow-up, and thereafter in accordance with Nexwift's Data Retention Policy. Records of security vulnerability reports and their handling are retained as security records for a period consistent with regulatory expectations for such records.

10. Governing Law and Jurisdiction

This policy, and any dispute or claim arising out of or in connection with it, is governed by the laws of the Kingdom of Saudi Arabia. The competent Saudi courts and authorities have exclusive jurisdiction. Nothing in this policy limits any right that a party has under mandatory law that cannot be excluded by agreement.

11. Changes to this Policy

Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms.

12. Contact

Purpose Contact
Security vulnerability reports info@nexwift.com (attn: Chief Information Security Officer)
Data protection matters info@nexwift.com (attn: Data Protection Officer)
General enquiries info@nexwift.com

This document is issued as a public statement of Nexwift's vulnerability disclosure practice. It does not create, and shall not be construed to create, any contractual right or obligation between Nexwift and any researcher, customer, beneficiary, or other party.

Launch login modal Launch register modal