Skip to content

Vulnerability Disclosure Policy

Applies to the iudexnc website (www.iudexnc.ai) and the iudexnc product application.

Effective from: 18 September 2026

iudexnc builds decision-support software for legal-protection insurers. The confidentiality of our customers' case data matters to us, and we value the work of security researchers who help us protect it. This policy explains how to report a vulnerability to us, what we ask of you, and what you can expect from us in return.

1. How to report

Send your report to security-notifications@iudexnc.ai. Please include:

  • the affected host, URL, endpoint or component;
  • the type of issue and its potential impact;
  • step-by-step instructions to reproduce it, with a minimal proof of concept;
  • any screenshots, request and response samples or logs that support the finding;
  • how you would like to be credited, if at all, and how we can reach you.

Our machine-readable contact details are published at /.well-known/security.txt (RFC 9116).

2. What you can expect from us

Our commitment
  • Acknowledgement of your report within 5 business days.
  • An initial assessment and severity rating within 10 business days.
  • Regular status updates while we work on a fix, at least every 30 days.
  • A fix or mitigation for confirmed vulnerabilities, prioritised by severity; critical issues are addressed as an incident.
  • Notification once the issue is resolved, and public credit if you wish.

We ask that you give us a reasonable time to fix a confirmed vulnerability before you disclose it publicly. Our default coordinated-disclosure window is 90 days from acknowledgement. We will agree an earlier date with you where a fix ships sooner, and we may ask for more time for issues that require changes at our customers.

3. Scope

The following systems operated by iudexnc are in scope:

  • iudexnc.ai and www.iudexnc.ai (this website);
  • app.iudexnc.ai (product application);
  • api.iudexnc.ai (product API);
  • official iudexnc source code and build artefacts where they are publicly reachable.

Please test only against accounts and data that belong to you. We do not provide test accounts for the product application; findings that can be demonstrated without an account, or from your own account, are welcome.

4. Out of scope

  • Services operated by third parties on our behalf (hosting, DNS and CDN providers, analytics, e-mail delivery, source-code hosting), unless the issue is caused by our configuration of them; please report those to the respective provider.
  • Denial of service, resource exhaustion, brute forcing, or any test that degrades availability for other users.
  • Social engineering, phishing, or physical attacks against iudexnc staff, customers or facilities.
  • Findings that require a compromised or rooted device, a man-in-the-middle position, or physical access to a user's machine.
  • Reports from automated scanners without a demonstrated, exploitable impact.
  • Missing security headers, best-practice deviations, version disclosures, or TLS configuration notes without a demonstrated impact.
  • Self-XSS, clickjacking on pages without sensitive actions, and missing rate limits on non-authentication endpoints.
  • E-mail configuration findings (SPF, DKIM, DMARC) without a demonstrated spoofing impact.

5. Rules of engagement

When testing, you must:

  • stop as soon as you have enough evidence to demonstrate the issue, and report it to us promptly;
  • not access, modify, download or delete data that is not your own; if you encounter customer or personal data, stop immediately, do not retain it, and tell us in your report;
  • not install persistence, pivot to other systems, or use a vulnerability beyond what is necessary to prove it;
  • not exfiltrate data beyond a minimal proof of concept, and not share it with anyone else;
  • not disrupt, degrade or overload the service;
  • not use social engineering, phishing or physical intrusion;
  • keep the details of the vulnerability confidential until we agree on disclosure;
  • comply with applicable law, including Swiss law and the law of your own jurisdiction.

6. Safe harbour

Good-faith research

If you conduct security research in good faith and in accordance with this policy, we consider it authorised. We will not initiate or support legal action against you for accessing our systems within the scope and rules above, and we will not report your research to law enforcement on that basis. If a third party initiates legal action against you for activity that complied with this policy, we will make it known that your actions were authorised by us.

This safe harbour does not cover conduct outside this policy, and it cannot bind third parties or authorities. If you are unsure whether a test is covered, ask us at security-notifications@iudexnc.ai before you proceed.

7. No bounty

iudexnc does not currently run a bug bounty programme and does not pay rewards for vulnerability reports. We recognise researchers who report in accordance with this policy with public credit on request. We may reconsider a rewards programme in the future; if we do, we will announce it on this page.

8. Reports and personal data

We use the information in your report only to investigate and fix the issue and to communicate with you about it. We keep your contact details for as long as the report is open and for our records afterwards. We may share technical details with affected customers or providers where a fix requires it, without naming you unless you agree. Our Privacy Policy applies.

9. Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new effective date. The version in force when a report is submitted applies to that report.

10. Contact

Vulnerability reports and questions about this policy: security-notifications@iudexnc.ai. For anything else, use contact@iudexnc.ai.