Skip to main content

Security Policy

Responsible Disclosure · Smart Zend LLC

Reporting a Vulnerability

If you discover a security vulnerability in Nilo AI, we encourage you to report it responsibly. We are committed to working with the security community to protect our users.

Send your findings to security@niloai.org. Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Any suggested fixes (optional)

Our Commitments

72h Acknowledgment

We acknowledge receipt within 72 hours

Weekly Updates

Updates every 7 days until resolution

No Legal Action

We do not pursue good-faith researchers

Public Credit

Optional Hall of Fame recognition

Scope

In scope: niloai.org, API endpoints (api.niloai.org), Chrome extension.

Out of scope: Third-party services (Stripe, Deepgram, Anthropic, Railway, Neon).

Security Measures

  • TLS 1.3 encryption in transit, AES-256 at rest
  • HSTS with preload enabled
  • OAuth 2.0 authentication (no password storage)
  • Rate limiting and bot protection on all endpoints
  • Security headers (CSP, X-Frame-Options, X-Content-Type-Options)
  • Automated dependency vulnerability scanning
  • Payment data processed by Stripe (PCI-DSS Level 1)

Security Contact

Email: security@niloai.org

Response time: 72 hours

Languages: Spanish, English

Entity: Smart Zend LLC

© 2026 Smart Zend LLC · Nilo AI