Vulnerability Disclosure Policy
NicNames, Inc. welcomes good-faith security research that helps protect CDN.MN, our Customers, and the public.
This Policy provides authorization and a safe-harbor framework for research conducted according to its terms. It does not authorize testing of Customer systems, Origins, third-party providers, or data that you do not own or have permission to access.
1. Contact
Report a suspected vulnerability to:
security@cdn.mn
Use subject:
Security Vulnerability Report
Include:
- affected hostname, URL, endpoint, package, or version;
- vulnerability type;
- clear reproduction steps;
- proof of concept;
- potential impact;
- affected Account, Site, or Agent, if your own;
- whether any data was accessed;
- suggested remediation, if available;
- your name or preferred attribution; and
- a secure way to contact you.
Do not send secrets, live tokens, or unnecessary personal data in ordinary email. Ask for a secure exchange method if needed.
2. In-scope systems
The following NicNames-controlled CDN.MN systems are generally in scope:
- https://cdn.mn;
- https://app.cdn.mn;
- published CDN.MN APIs and well-known metadata;
- the CDN.MN MCP endpoint;
- @cdnmn/cli;
- @cdnmn/sdk;
- generated delivery hostnames assigned to an Account you own or are expressly authorized to test; and
- other systems that NicNames expressly identifies as in scope.
3. Out-of-scope systems and activity
The following are out of scope unless NicNames provides prior written authorization:
- Customer Origins, websites, applications, custom domains, repositories, or data;
- another Customer's generated hostname;
- third-party infrastructure or services;
- social engineering, phishing, or physical testing;
- denial-of-service, stress, load, resource-exhaustion, or traffic-amplification testing;
- attempts to access private networks or metadata services;
- malware, ransomware, persistence, or destructive payloads;
- automated scanning that creates material traffic or cost;
- extraction of Customer Content;
- modification, deletion, corruption, or public disclosure of data;
- payment fraud or use of stolen payment methods;
- employee or contractor targeting;
- spam;
- credential stuffing;
- testing that violates law or a third party's terms; and
- reports consisting only of scanner output without a demonstrated security impact.
Generally excluded findings include:
- missing security headers without an exploitable consequence;
- self-XSS;
- clickjacking on pages without a sensitive action;
- denial of service;
- version disclosure;
- rate-limit observations that do not enable meaningful abuse;
- user or email enumeration without demonstrated exposure beyond normal product behavior;
- vulnerabilities solely in obsolete browsers;
- theoretical attacks requiring unrealistic conditions; and
- issues already publicly known and undergoing remediation.
We may still accept useful reports outside this list at our discretion.
4. Research rules
To qualify as good-faith research:
- Use only Accounts, Workspaces, Sites, Origins, domains, content, tokens, payment methods, and repositories that you own or are authorized to test.
- Create the minimum proof necessary to demonstrate the issue.
- Stop immediately if you encounter another person's data.
- Do not retain, copy, disclose, or alter another person's data.
- Do not degrade availability or create material cost.
- Respect rate limits and approval gates.
- Do not bypass a human approval by tricking or coercing a user.
- Do not test a Customer's Origin through CDN.MN without that Customer's authorization.
- Do not publicly disclose the issue before coordinated disclosure.
- Report promptly and cooperate in verification.
- Comply with applicable law.
5. Safe harbor
If you conduct research in good faith and in compliance with this Policy, NicNames will:
- consider the research authorized under applicable computer-access laws for the limited purpose of identifying and reporting the vulnerability;
- not initiate legal action against you for the compliant research;
- not assert a Digital Millennium Copyright Act anti-circumvention claim based solely on the compliant research; and
- attempt to clarify any uncertainty before treating your conduct as noncompliant.
This safe harbor does not:
- bind a third party;
- authorize violation of another person's rights;
- waive claims concerning conduct outside this Policy;
- protect extortion, threats, data misuse, fraud, or bad-faith conduct; or
- create a monetary reward.
If a third party initiates legal action concerning compliant research, we may confirm that the activity was conducted under this Policy where appropriate and lawful.
6. Our response goals
We aim to:
- acknowledge a complete report within three business days;
- provide an initial assessment within ten business days;
- keep the reporter reasonably informed of material remediation progress; and
- coordinate a disclosure date appropriate to the risk.
These are targets, not contractual guarantees. Complex or provider-dependent issues may require more time.
7. Coordinated disclosure
Do not publicly disclose a vulnerability until:
- NicNames confirms remediation;
- the parties agree on a disclosure date; or
- ninety days have passed after a complete report and you have given reasonable notice of intended disclosure.
We may request additional time for a complex issue where active exploitation is not occurring and the delay is reasonable.
Do not disclose Customer identity, Customer Content, secrets, exploit details that materially endanger users, or information restricted by law.
8. Recognition and rewards
CDN.MN does not promise a bounty or payment. We may provide acknowledgment or another discretionary reward.
Do not condition nondisclosure, deletion of data, or nonexploitation on payment.
9. Security incidents and abuse
Use security@cdn.mn for product vulnerabilities.
Use abuse@cdn.mn for phishing, malware, illegal content, copyright, compromised Customer sites, or policy violations.
Use support@cdn.mn for ordinary configuration or availability problems.
10. Changes
We may update this Policy. Research is governed by the version in effect when the relevant testing occurred, unless a later version is more favorable to the researcher.