Security & Vulnerability Disclosure Policy

Last updated: October 2026

1. Our Security Philosophy

NexaTools operates under a strict local-first architecture. The vast majority of our tools execute entirely within your browser using JavaScript and WebAssembly. We do not transmit, process, or store your personal files, images, code snippets, or documents on our servers.

Because your sensitive data never touches our infrastructure, the risk of data breaches affecting user files is fundamentally eliminated by design.

2. Vulnerability Disclosure Policy (VDP)

We take the security of our website, backend APIs (such as the URL Shortener), and infrastructure seriously. If you believe you have found a security vulnerability in NexaTools, we encourage you to let us know right away.

3. Scope

The following are in scope for our vulnerability disclosure policy:

4. Out of Scope

Because of our local-first architecture, certain reports are fundamentally inapplicable and will be closed as out-of-scope:

5. Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will make it known that your actions were conducted in compliance with this policy.

6. Contact

For any security-related inquiries, please email support@nexatools.in.