We take the security of our platform seriously. If you believe you've found a security vulnerability in a Nexora system, we encourage you to report it responsibly under the terms below.
Test only assets listed in scope. Do not access, modify or destroy other users' data beyond what is needed to demonstrate a vulnerability. Use only your own test accounts. Report promptly and keep details private until we have resolved the issue.
| Asset | Type | Status |
|---|---|---|
javohir.com.uz (www) | Marketing site | IN SCOPE |
app.javohir.com.uz | Customer web app | IN SCOPE |
api.javohir.com.uz | Public REST API | IN SCOPE |
admin.javohir.com.uz | Admin console | IN SCOPE |
staging.javohir.com.uz / dev.javohir.com.uz | Pre-production | IN SCOPE |
legacy.javohir.com.uz | Legacy reporting tool | IN SCOPE |
docs.javohir.com.uz, status.javohir.com.uz | Docs / status | IN SCOPE |
Any other *.javohir.com.uz subdomain you discover | Owned by Nexora | IN SCOPE |
| Physical attacks, social engineering, phishing of Nexora staff or users | OUT |
| Denial of Service (DoS/DDoS), volumetric or resource-exhaustion testing | OUT |
| Automated scanning that generates excessive traffic (throttle your tools) | OUT |
Third-party services & domains that are not *.javohir.com.uz | OUT |
| Reports from automated tools without a demonstrated, reproducible impact | OUT |
| Missing security headers / best-practice suggestions with no exploit path | OUT |
| The domain registrar, DNS provider, mail provider, or your own VPS host | OUT |
app.javohir.com.uz).*.javohir.com.uz. If SSRF/redirect lets you reach other hosts, stop and report — do not pivot.| Severity | Examples | Reward |
|---|---|---|
| Critical | RCE, full auth bypass, SQLi dumping other tenants, admin takeover | $$$$ |
| High | IDOR to other tenants' data, privilege escalation, SSRF to internal, stored XSS in app | $$$ |
| Medium | Reflected XSS, sensitive info leak (debug/config), open redirect chained | $$ |
| Low | Verbose errors, predictable tokens without takeover, CORS without impact | $ |
Email security@javohir.com.uz with: title, affected asset/URL, severity, step-by-step reproduction, proof-of-concept, and impact. One vulnerability per report.
Researchers who report valid issues are acknowledged here.