Nexad · Vulnerability Disclosure

Nexad Vulnerability Disclosure

Vulnerability disclosure

Nexad runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyArtificial IntelligenceAdvertisingMarketingMarketing AutomationContextual AdvertisingMobile SDKAgent
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@soku.ai
Contact
https://github.com/About-Intelligence/soku-cli/security/advisories/new

Source

Vulnerability Disclosure

nexad-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
product: Nexad / Soku (About Intelligence, Inc.)
notes: >-
  Nexad publishes a real, specific vulnerability-disclosure policy — but NOT where
  the standard probes look. /.well-known/security.txt returns 404 on nex.ad,
  soku.ai and docs.nex.ad, and /security and /trust are 404 on soku.ai, so the
  deterministic probe (probe-security-programs.py) recorded vdp=none. The policy
  lives in SECURITY.md at the root of the company's public GitHub repository,
  About-Intelligence/soku-cli, which the GitHub org (login About-Intelligence,
  display name "Nexad", blog https://nex.ad, email ceo@nex.ad) plainly owns. It
  names a private reporting channel, a security mailbox, a required report format,
  an acknowledgement SLA and a supported-versions statement. Recording it here is a
  search hit, not an inference. The gap worth flagging to the provider is
  distribution, not substance: a two-line /.well-known/security.txt pointing at
  this policy would make it machine-discoverable.
policy:
  - https://github.com/About-Intelligence/soku-cli/blob/main/SECURITY.md
contact:
  - security@soku.ai
  - https://github.com/About-Intelligence/soku-cli/security/advisories/new
reporting:
  private_channel: GitHub private vulnerability reporting
  email: security@soku.ai
  public_issues_prohibited: true
  required_details:
    - Description of the vulnerability and its impact
    - Steps to reproduce, with a proof of concept where available
    - Affected version (`soku --version`)
acknowledgement_sla: 3 business days
remediation_timeline: Provided after triage.
supported_versions:
  policy: Security fixes are applied to the latest published release on npm (@soku-ai/cli). Older versions are not maintained.
credential_handling: >-
  The policy documents local token storage (OS keychain via keytar when available,
  otherwise a file-backed store), instructs reporters never to paste tokens into
  issues, logs or pull requests, and gives an explicit rotation path
  (`soku auth logout` then `soku auth login`).
bug_bounty:
  present: false
  platform: null
  note: No HackerOne / Bugcrowd / Intigriti program found.
evidence:
  - source: https://raw.githubusercontent.com/About-Intelligence/soku-cli/main/SECURITY.md
    kind: SECURITY.md
    http_status: 200
    fetched: '2026-08-13'
    file: security/nexad-security-policy.md
  - source: https://api.github.com/orgs/About-Intelligence
    kind: ownership-verification
    http_status: 200
    detail: 'GitHub org About-Intelligence: name "Nexad", blog https://nex.ad, email ceo@nex.ad'
    fetched: '2026-08-13'
  - source: https://nex.ad/.well-known/security.txt
    kind: negative-probe
    http_status: 404
    fetched: '2026-08-13'
  - source: https://soku.ai/.well-known/security.txt
    kind: negative-probe
    http_status: 404
    fetched: '2026-08-13'