Skip to main content
NEOMANERA
  • Products
  • Capabilities
  • Engineering
  • Company
  • Support
  • Contact
Contact us
  • Products
  • Capabilities
  • Engineering
  • Company
  • Support
  • Contact
Contact us
  1. Home
  2. Responsible disclosure

Legal

Responsible disclosure

If you have found a security vulnerability in one of our products or systems, we want to hear about it. This page explains how to report it and what we commit to in return.

In effect from 18 September 2026

On this page

  • Our commitment
  • Scope
  • How to report
  • What to expect
  • Research guidelines
  • Safe harbour
  • Out of scope
  • Recognition

Our commitment

We take security reports seriously and we treat the people who make them as collaborators rather than as a nuisance. We will not take legal action against anyone who reports a vulnerability in good faith and follows this policy.

Scope

This policy covers:

  • the website at neomanera.co.uk;
  • software products published by NEOMANERA LTD;
  • the online services those products depend on.

It does not cover systems operated by third parties — including application stores, payment providers and hosting platforms. Please report issues in those systems to their own security teams.

How to report

Email developer@neomanera.co.uk with “Security” in the subject line. A useful report includes:

  • the product, service or URL affected, and the version if applicable;
  • a description of the vulnerability and why you believe it is exploitable;
  • clear steps to reproduce it, including any request or payload used;
  • your assessment of the impact;
  • whether any third party is aware of the issue.

Please report in English where you can. If you wish to encrypt your report, write first and we will arrange a key.

Please do not open a public issue, post the details publicly, or demonstrate the vulnerability against real user data before we have had a chance to fix it.

What to expect

Stage Our commitment
Acknowledgement Within 2 working days of receipt
Initial assessment Within 10 working days, including our severity view
Progress updates At least every 14 days until the issue is closed
Remediation target 90 days from acknowledgement, and sooner for high-severity issues
Disclosure Coordinated with you once a fix is available

If we disagree with your assessment, we will explain our reasoning rather than simply closing the report.

Research guidelines

When testing, please:

  • use only your own accounts and your own data;
  • stop as soon as you have established that a vulnerability exists — do not enumerate records, pivot further into a system, or read other people’s data;
  • avoid anything that degrades service for others: no denial-of-service testing, no automated scanning at volume, no spam;
  • delete any data you obtained incidentally once you have reported, and tell us what you obtained;
  • give us reasonable time to remediate before disclosing publicly.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will regard your activity as authorised, we will not initiate or support legal action against you in relation to it, and we will not report you to law enforcement for it. If a third party brings legal action against you for research that complied with this policy, we will make that compliance known.

This safe harbour does not extend to accessing or exfiltrating other people’s data, to disrupting our services, or to extortion. A report accompanied by a demand for payment in exchange for withholding disclosure is not a security report and will be treated accordingly.

Out of scope

The following are generally not treated as vulnerabilities on their own, though we will still read a report that demonstrates real impact:

  • missing security headers with no demonstrated exploit;
  • findings from an automated scanner without a working proof of concept;
  • reports about software versions, with no demonstrated vulnerable path;
  • social engineering of our staff, and physical attacks;
  • self-inflicted issues requiring an already-compromised or rooted device;
  • email configuration findings — SPF, DKIM, DMARC — with no demonstrated impact;
  • absence of rate limiting on an endpoint with no sensitive action behind it.

Recognition

We do not currently operate a paid bug bounty. We do offer public credit: if you would like to be acknowledged for a valid report, tell us the name or handle you would like us to use and we will credit you when we publish the fix. If you would prefer to remain anonymous, that is equally fine.

A machine-readable version of this contact information is published at /.well-known/security.txt.

NEOMANERA

Building software for a new way forward.

NEOMANERA LTD 71-75 Shelton StreetCovent GardenLondonWC2H 9JQUnited Kingdom developer@neomanera.co.uk

Products

  • All products
  • Manera Connect
  • Manera Focus
  • Product support

Company

  • About NEOMANERA
  • Capabilities
  • Engineering
  • Careers
  • Brand

Resources

  • Contact
  • Company information
  • Responsible disclosure
  • Accessibility
  • Sitemap

Legal

  • Privacy policy
  • Terms of use
  • Cookie policy
  • Acceptable use

NEOMANERA LTD is a private company limited by shares registered in England and Wales, company number 17462296. D-U-N-S number 235161776. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

© 2026 NEOMANERA LTD. All rights reserved.

  • Privacy
  • Terms
  • Cookies
  • Company information