Security Contact & Incident Response

Your security is our top priority. This page provides contact information for security incidents, vulnerability reports, and emergency situations.

Contact Methods

General Security Inquiries

Response time: 24–48 hours
Use for: Non-urgent security questions, general inquiries

Urgent Security Issues

Subject: URGENT - [Brief Description]
Response time: < 4 hours (business hours)
Use for: Active attacks, critical vulnerabilities, data exposure

Responsible Disclosure

Subject: Security Vulnerability Report
Response time: < 24 hours
Use for: Security vulnerability reports in NautilloPro platform

Legal & Compliance

Subject: Legal Notice
Response time: 24–48 hours
Use for: GDPR requests, subpoenas, legal notices

Privacy & Data Requests

Subject: Privacy Request
Response time: 5 business days
Use for: GDPR data subject requests (access, deletion, portability), privacy concerns

Incident Severity Levels

We classify incidents into severity levels to ensure appropriate response times. Understanding these levels helps you communicate urgency effectively.

P0 - CRITICAL
Response time: < 15 minutes (business hours) / < 4 hours (out of hours)

Examples:

  • Active data breach with customer data exposed
  • Platform-wide outage affecting all users
  • Zero-day vulnerability being actively exploited
  • Ransomware or malware infection
  • Customer simulation caused significant confirmed damage
P1 - HIGH
Response time: < 1 hour

Examples:

  • Partial data exposure (limited customer data)
  • Major feature outage (simulations disabled)
  • High-severity security vulnerability discovered
  • Compliance violation detected (GDPR, PCI-DSS)
  • Unauthorized access to non-critical systems
P2 - MEDIUM
Response time: < 4 hours

Examples:

  • Individual customer simulation failure
  • Intermittent performance degradation
  • Medium-severity security vulnerability
  • Customer AUP violation (unauthorized simulation)
  • Billing discrepancy or payment issue
P3 - LOW
Response time: < 24 hours

Examples:

  • Minor UI or cosmetic issues with no security impact
  • Low-severity security observations (informational findings)
  • Non-urgent documentation or policy questions
  • General security hygiene recommendations

Responsible Disclosure Program

We welcome security researchers to report vulnerabilities responsibly. We are committed to working with the security community to protect our users.

1

1. Identify

Discover a potential security vulnerability in NautilloPro

2

2. Report

Email support@nautillo.pro with subject 'Security Vulnerability Report' — do not publicly disclose

3

3. Acknowledgment

We respond within 24 hours acknowledging receipt

4

4. Triage

We assess severity and validate the report within 48 hours

5

5. Fix

We develop and deploy a fix based on severity (1–30 days)

6

6. Disclosure

Coordinated public disclosure after fix is deployed (with your credit if desired)

Our Commitments

Rapid Response

We acknowledge all security reports within 24 hours and provide regular updates throughout the investigation and remediation process.

Coordinated Disclosure

We work with researchers to coordinate public disclosure after fixes are deployed, giving you proper credit for your discovery if you wish.

Legal Protection

Good faith security research conducted within the scope of our responsible disclosure guidelines is protected. We will not pursue legal action against researchers who follow these guidelines.

GDPR Breach Notification

In the event of a personal data breach, we notify the Estonian Data Protection Inspectorate within 72 hours per GDPR Article 33, and affected customers without undue delay where required under Article 34.

Additional Resources