Security
Vulnerability Disclosure
nproxima GmbH · Last updated October 2026
Reporting a Vulnerability
nproxima GmbH takes the security of its products and websites seriously. If you believe you have found a security vulnerability in co-mind.ai or on one of our websites, please report it to us at support@co-mind.ai with the subject line "Security vulnerability".
Please include as much of the following as you can:
- A description of the vulnerability and its potential impact
- The affected product, component, version, or URL
- Steps to reproduce, a proof of concept, or relevant logs
- How we can reach you for follow-up questions
Please share only the information needed to understand and reproduce the issue, and do not include personal data of third parties. If you need an encrypted channel, say so in your first message and we will arrange one.
Scope
This policy covers:
- The co-mind.ai platform and all of its software components distributed by nproxima GmbH
- Our websites co-mind.ai, docs.co-mind.ai and nproxima.ai
Vulnerabilities in third-party products that we use should be reported to the respective vendor. If such a vulnerability affects co-mind.ai, we are glad to receive a copy of your report.
What Happens Next
After receiving your report, we will:
- Confirm that we have received it
- Assess and prioritise the vulnerability and keep you informed of our progress
- Develop and release a fix or mitigation, and inform affected customers and partners
- Credit you for the discovery once the issue is resolved, if you wish
Where required by law, in particular by the EU Cyber Resilience Act, we report actively exploited vulnerabilities and severe security incidents to the competent authorities.
Coordinated Disclosure
We ask you to give us reasonable time to investigate and fix the issue before you disclose it publicly, and to coordinate the timing of any publication with us.
Guidelines for Security Research
When investigating a vulnerability, please:
- Do not access, modify, or delete data that does not belong to you, and stop as soon as you encounter personal data or confidential information
- Do not perform denial-of-service attacks, social engineering, phishing, or physical attacks
- Do not use automated scanners in a way that degrades our services
- Use only the minimum access necessary to demonstrate the vulnerability
Reports from automated tools without a demonstrated security impact, and missing best-practice settings without an exploitable risk, are generally not considered vulnerabilities.