Report a vulnerability
Last updated 24 July 2026
Security researchers are welcome here. If you believe you have found a vulnerability in our website or services, we would like to hear about it as soon as possible, so we can fix it before others abuse it.
How to report
Email your findings to info@nexg3n.com. If you prefer encrypted email, our public PGP key is available at https://nexg3n.com/.well-known/pgp-key.txt. For automated discovery we also publish a security.txt file according to RFC 9116 at https://nexg3n.com/.well-known/security.txt. Describe what you found, the steps needed to reproduce it and, if you wish, how we can reach you with questions.
What we ask of you
Give us a reasonable period to fix the problem before publishing anything about it. Do not go further than necessary to demonstrate the vulnerability: do not view, modify or delete other people’s data, do not install malware and do not maintain access. Do not use social engineering, physical intrusion or attacks that affect the availability of our services, such as ddos or spam.
What we promise
We confirm your report as soon as possible, usually within two business days, and keep you informed of the follow-up. If you report in good faith and within the rules above, we will not take legal action against you. This policy follows the Coordinated Vulnerability Disclosure guideline of the Dutch National Cyber Security Centre (NCSC). If you like, we credit you by name when the fix ships, or we keep your report fully confidential if you prefer.
Abuse reports too
If you see abuse running through our services or infrastructure, for example phishing or spam from an environment we host, please also report it via info@nexg3n.com. This address is our central point of contact for authorities and users, including within the meaning of the European Digital Services Act.