NexLife welcomes reports from independent security researchers and customers. If you believe you have found a vulnerability, please contact us before disclosing it publicly.
How to Report
Email security@nexlifecrm.org with:
- A clear description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions, including URLs, request payloads, and any accounts involved.
- Whether you have shared the finding with anyone else.
- Whether you are open to being credited if we choose to acknowledge reporters.
What to Expect
- We will acknowledge good-faith reports within a reasonable time.
- We will investigate and, where confirmed, work on a remediation timeline appropriate to severity.
- We may follow up for clarification. Please do not exfiltrate data, test with real client PII, or disrupt production for other users.
Safe Harbor
If you make a good-faith effort to comply with this policy, no data exfiltration, no privacy violations of third parties, no service disruption, no social engineering of NexLife staff or customers, we will not pursue legal action against you for the research activity itself, and we will work with you to promptly understand and resolve the issue. This safe harbor does not extend to violations of applicable law or to attacks on customer accounts you do not own.
Out of Scope
- Denial-of-service or volumetric attacks.
- Reports based solely on missing headers, banner grabs, or automated scanner output without demonstrated impact.
- Vulnerabilities in third-party services (Stripe, Supabase, Cloudflare, Resend, etc.), please report those directly to the vendor.
- Social-engineering of NexLife employees, contractors, or customers.
General Support
For non-security questions, use nexlifecrm.info@gmail.com or call (888) 863-9189.
