Bug Bounty
NezzAI.com Bug Bounty Policy
1. Introduction
NezzAI.com is committed to maintaining a secure, reliable, and trustworthy AI-powered platform for freelancers, SMEs, businesses, organizations, and other users. Our Bug Bounty Program encourages security researchers, developers, and ethical hackers to responsibly identify and report potential security vulnerabilities affecting NezzAI websites, applications, APIs, AI services, integrations, accounts, and other eligible platform components. This program supports our ongoing efforts to strengthen security across all NezzAI plans, from Beginner and Basic through Starter, Professional, Business, Ultimate, and Enterprise.
2. Purpose of the Bug Bounty Policy
The purpose of the NezzAI Bug Bounty Program is to strengthen platform security through responsible collaboration with the cybersecurity community. By identifying and addressing vulnerabilities before they can cause harm, NezzAI aims to protect user accounts, business information, AI-generated content, websites, mobile applications, SaaS platforms, integrations, communications, payment-related information, and other platform functionality.
3. Scope of Security Testing
The Bug Bounty Program may cover eligible NezzAI websites, applications, APIs, AI-powered services, website-generation systems, account functionality, dashboards, integrations, SaaS services, and other systems officially designated as within scope. Researchers must only test systems and functionality that NezzAI has authorized under this program and must avoid activities that could disrupt services, affect other users, damage systems, or expose confidential information.
4. Responsible Vulnerability Disclosure
NezzAI requires security researchers to follow responsible vulnerability disclosure practices when reporting potential security issues. Reports should include sufficient technical information, affected URLs or components, reproduction steps, evidence or proof of concept where appropriate, potential security impact, and recommended remediation guidance. Researchers should provide NezzAI with a reasonable opportunity to investigate and address reported vulnerabilities before publicly disclosing them.
5. Protection of User Data and Privacy
Security testing must respect the privacy, confidentiality, and security of NezzAI users and their information. Researchers must not intentionally access, modify, download, copy, disclose, or retain personal information, business data, account credentials, AI-generated content, customer information, payment information, private communications, or other confidential data beyond what is strictly necessary to demonstrate a vulnerability. Any accidentally accessed information must be immediately protected and reported to NezzAI.
6. Security Coverage Across NezzAI Plans
NezzAI applies security practices across its available subscription plans, including Beginner, Basic, Starter, Professional, Business, Ultimate, and Enterprise. These plans provide different levels of AI solutions, automation, content creation, website generation, social media capabilities, integrations, storage, applications, SaaS functionality, and other services. Security remains an important consideration across the NezzAI platform regardless of the user’s selected plan or service level.
7. Plan-Specific Features and Security Considerations
NezzAI subscription plans provide progressively expanded capabilities, including increased AI solution selections, social media automation, content creation, AI-generated images and videos, AI chatbots, email marketing, website generation, dashboards, brand tools, and other functionality. As users access more advanced capabilities, researchers may identify security considerations involving additional features, integrations, APIs, workflows, or data flows. Such issues should be responsibly reported through the Bug Bounty Program.
8. Business and Advanced AI Platform Security
NezzAI plans such as Starter, Professional, Business, and Ultimate provide increasingly advanced capabilities, including AI sales automation, CRM integration, AI forecasting, content workspaces, team functionality, analytics, website generation, SaaS subscription platforms, and AI mobile application generation. Security testing may therefore include eligible interactions between these capabilities, provided researchers remain within the authorized scope and do not disrupt services or access information belonging to other users.
9. Enterprise Security Commitment
NezzAI Enterprise services are designed for organizations requiring customized quantities, advanced AI capabilities, integrations, managed cloud hosting, custom AI knowledge bases, CRM and API integrations, MCP integration, SaaS platforms, websites, mobile applications, multilingual capabilities, and other customized solutions. Enterprise security requirements may vary according to the customer’s configuration and service agreement. Researchers must only test Enterprise environments where explicit authorization has been provided by NezzAI.
10. Websites, SaaS Platforms, Mobile Apps, and AI Services
NezzAI provides website generation, multi-tenant SaaS subscription platforms, AI mobile application generation, AI solutions, automation, integrations, and other digital services across applicable plans. Security vulnerabilities involving these components may be eligible for consideration when they are within the officially authorized Bug Bounty scope. Researchers must not test third-party services, customer-owned systems, app-store infrastructure, hosting providers, or external integrations unless NezzAI has expressly authorized such testing.
11. Eligible Bug Reports
Eligible reports may include security vulnerabilities such as authentication or authorization weaknesses, account takeover risks, privilege escalation, sensitive data exposure, insecure API behavior, injection vulnerabilities, cross-site scripting, server-side security issues, business logic vulnerabilities, insecure integrations, and other technical weaknesses that could materially affect the confidentiality, integrity, or availability of NezzAI services. Reports should clearly explain the vulnerability, affected component, reproduction method, and potential impact.
12. Non-Eligible Reports
The Bug Bounty Program generally does not cover general feedback, feature requests, ordinary usability issues, cosmetic defects, unsupported configurations, automated scanner results without meaningful validation, spam, social engineering, phishing, denial-of-service or disruptive testing, physical attacks, vulnerabilities in unrelated third-party services, or issues that do not present a meaningful security risk. Researchers should not attempt to obtain, alter, delete, or expose another user’s information.
13. Security Improvements and Continuous Monitoring
NezzAI continuously reviews and improves its security practices, technology infrastructure, applications, APIs, AI services, integrations, and operational processes. Security reports submitted through the Bug Bounty Program help NezzAI identify potential weaknesses, prioritize remediation, strengthen defensive measures, and improve the reliability and security of services provided across its subscription plans and customized Enterprise solutions.
14. Collaboration with Security Researchers
NezzAI values responsible security researchers, developers, and ethical hackers who contribute to improving the safety of the platform. Researchers who follow this policy, respect user privacy, avoid disruptive activities, and responsibly disclose vulnerabilities help NezzAI build a stronger and more secure AI ecosystem for freelancers, SMEs, businesses, organizations, and users worldwide.
15. Updates to the Bug Bounty Policy
NezzAI reserves the right to modify, update, expand, or otherwise improve this Bug Bounty Policy as its technology, AI capabilities, subscription plans, applications, integrations, infrastructure, security practices, and services evolve. The scope of eligible systems and reporting requirements may also change over time. Researchers are encouraged to review the latest version of this policy and any officially published Bug Bounty scope before conducting security testing or submitting vulnerability reports.