Security Contact & Incident Response
Your security is our top priority. This page provides contact information for security incidents, vulnerability reports, and emergency situations.
Email support@nautillo.pro with subject "URGENT" for immediate response.
P0 incidents are acknowledged within 15 minutes during business hours and within 4 hours outside business hours. For active data breaches, we notify the Estonian Data Protection Inspectorate within 72 hours per GDPR Article 33.
Contact Methods
General Security Inquiries
Urgent Security Issues
Responsible Disclosure
Legal & Compliance
Privacy & Data Requests
Incident Severity Levels
We classify incidents into severity levels to ensure appropriate response times. Understanding these levels helps you communicate urgency effectively.
Examples:
- •Active data breach with customer data exposed
- •Platform-wide outage affecting all users
- •Zero-day vulnerability being actively exploited
- •Ransomware or malware infection
- •Customer simulation caused significant confirmed damage
Examples:
- •Partial data exposure (limited customer data)
- •Major feature outage (simulations disabled)
- •High-severity security vulnerability discovered
- •Compliance violation detected (GDPR, PCI-DSS)
- •Unauthorized access to non-critical systems
Examples:
- •Individual customer simulation failure
- •Intermittent performance degradation
- •Medium-severity security vulnerability
- •Customer AUP violation (unauthorized simulation)
- •Billing discrepancy or payment issue
Examples:
- •Minor UI or cosmetic issues with no security impact
- •Low-severity security observations (informational findings)
- •Non-urgent documentation or policy questions
- •General security hygiene recommendations
Responsible Disclosure Program
We welcome security researchers to report vulnerabilities responsibly. We are committed to working with the security community to protect our users.
1. Identify
Discover a potential security vulnerability in NautilloPro
2. Report
Email support@nautillo.pro with subject 'Security Vulnerability Report' — do not publicly disclose
3. Acknowledgment
We respond within 24 hours acknowledging receipt
4. Triage
We assess severity and validate the report within 48 hours
5. Fix
We develop and deploy a fix based on severity (1–30 days)
6. Disclosure
Coordinated public disclosure after fix is deployed (with your credit if desired)
- • Detailed description of the vulnerability
- • Steps to reproduce the issue
- • Potential impact summary
- • Proof-of-concept (if applicable)
- • Your contact information for follow-up
Our Commitments
Rapid Response
We acknowledge all security reports within 24 hours and provide regular updates throughout the investigation and remediation process.
Coordinated Disclosure
We work with researchers to coordinate public disclosure after fixes are deployed, giving you proper credit for your discovery if you wish.
Legal Protection
Good faith security research conducted within the scope of our responsible disclosure guidelines is protected. We will not pursue legal action against researchers who follow these guidelines.
GDPR Breach Notification
In the event of a personal data breach, we notify the Estonian Data Protection Inspectorate within 72 hours per GDPR Article 33, and affected customers without undue delay where required under Article 34.