\u0273Self
HomeMembershipCloudClawChatTaskDocs
GitHubGet Started

Product

  • Docs
  • Membership
  • Cloud
  • Changelog

Apps

  • ɳChat
  • ɳClaw
  • ɳTask

Community

  • GitHub
  • Discord
  • Blog

Legal

  • Privacy
  • Terms
ɳSelf

© 2026 ɳSelf. All rights reserved.

ɳSelfɳSELFCLI
DocsComparePricingChangelogBlogɳCloud
19★

Security Policy

Responsible disclosure policy for nSelf and related services.

Scope

The following assets are in scope for security reports:

  • nSelf CLI (nself-org/cli)
  • nSelf plugins (nself-org/plugins, nself-org/plugins-pro)
  • nself.org and all subdomains (*.nself.org)
  • Docker images published under nself/

Out of scope

  • Third-party dependencies (report upstream)
  • Social engineering attacks
  • Denial of service attacks
  • Issues in self-hosted instances caused by user misconfiguration

Rules

  • Do not access or modify other users' data
  • Do not disrupt services or degrade performance
  • Do not publicly disclose before we have fixed the issue
  • Provide enough detail for us to reproduce the issue

Safe Harbor

If you follow this policy in good faith, we will not pursue legal action against you. We consider security research conducted under this policy to be authorized and will not file complaints with law enforcement.

Response SLAs

SeverityAcknowledgementInitial assessmentFix target
Critical48 hours5 days7 days
High48 hours5 days30 days
Medium48 hours5 days90 days
Low48 hours10 daysBest effort

Public disclosure

We coordinate public disclosure 90 days after the fix is released. We will credit you in the security advisory unless you prefer to remain anonymous.

Recognition

We maintain a Hall of Fame for security researchers who report valid vulnerabilities. Monetary bounties via HackerOne are planned within 12 months.

Contact

Email: security@nself.org
Report form: nself.org/security/report