Do not open a public issue for a suspected vulnerability or include private Human material in a report.
Email contact@nexah.de with the subject
[SECURITY] NEXAHEDRON. Include:
- the affected version, revision or public URL;
- a minimal reproduction;
- the expected and observed behavior;
- the likely impact;
- whether Human material, credentials or provenance may have been exposed.
Never send real secrets, access tokens or third-party personal material. Use redacted or synthetic examples.
Receipt should be acknowledged within seven calendar days. Acknowledgement is not confirmation of a vulnerability or a promise of a remediation date.
Only the latest explicitly published NEXAHEDRON release is eligible for security fixes. Working-tree snapshots, historical Alpha records and forks are not supported releases. Until a first release is published, no version is represented as production-supported.
Reports may cover the NEXAHEDRON application, its same-origin transport route, deployment configuration and accidental disclosure of Human material. Vulnerabilities in NEXAH, ORION, hosting providers or external sources should also be reported to their respective owners. NEXAHEDRON will not silently assume another subsystem's authority.