Skip to main content
nowhere
  • Home
  • Consulting
  • Catalysis
  • Catalyst Praxeum
  • Catalyst curriculum
  • Meeting Craft
  • About Us
Client login

Terms & Privacy

get in touch

Responsible Disclosure Policy

Last updated - 3 March 2026

1. Purpose

1.1 The purpose of this policy is to establish the responsible approach that independent security researchers should adhere to when reporting on any security vulnerabilities that may be found on any of Nowhere Group Limited's ('nowhere') online services, software and products ('Applications').

2. Scope

2.1 This policy applies to all security researchers, as well as nowhere employees ('Staff'), consultants, contractors and associates operating on behalf of nowhere, who have access to nowhere's Applications.

3. nowhere Commitment

3.1 We take the protection of Personal and Confidential Client and Company Data as defined in the Data Handling Policy very seriously and encourage responsible reporting of any vulnerabilities that may be found on our Applications.

3.2 We knowledge the valuable role that independent security researchers play in improving internet security and nowhere's overall security posture.

3.3 We commit to working with security researchers to verify and address any potential vulnerabilities that are reported to us.

3.4 We pledge not to initiate legal action against security researchers for penetrating or attempting to penetrate our systems as long as they adhere to this policy.

3.5 As a component of responsible disclosure, nowhere will notify potentially impacted clients and end users when they must take action to patch or otherwise remediate a vulnerability in advance of publicly disclosing the issue.

4. Reporting Potential Security Vulnerabilities

4.1 Always use test or demo accounts when testing our Applications.

4.2 Privately share details of the suspected vulnerability with nowhere by sending an email to security@now-here.com.

4.3 Provide full details of the suspected vulnerability so the nowhere Security Team may validate and reproduce the issue.

4.4 Once a vulnerability report has been submitted responsibly, the nowhere Security Team and associated development teams will use reasonable efforts to:

4.4.1 Respond in a timely manner, acknowledging receipt of the vulnerability report.

4.4.2 Provide an estimated time frame for addressing the vulnerability report.

4.4.3 Notify the researcher when the vulnerability has been fixed.

5. Coordinated Disclosure Timeline

5.1 nowhere follows a coordinated vulnerability disclosure approach, working with security researchers to remediate issues responsibly before public disclosure.

5.2 The standard remediation timeline is:

5.2.1 Initial acknowledgement: within 5 working days.

5.2.2 Target remediation window: 30 / 60 / 90 days, depending on severity and complexity.

5.3 Timelines may be adjusted in line with risk assessment and business impact, in accordance with the Incident Management Policy, ISMS Policy, and Risk Management processes.

6. Secure Vulnerability Reporting

6.1 Security researchers are encouraged to submit vulnerability details using encrypted communication where possible.

6.2 nowhere will provide a secure file-sharing method for the transmission of sensitive vulnerability information.

6.3 Encryption and secure handling of vulnerability data is managed in line with the Cryptography Policy and Access Control Policy.

7. Prohibited Types of Security Research

7.1 Performing actions that may negatively affect nowhere, its clients or end users (e.g. Spam, Brute Force, Denial of Service…).

7.2 Accessing, or attempting to access, data or information that does not belong to you.

7.3 Destroying or corrupting, or attempting to destroy or corrupt, data or information that does not belong to you.

7.4 Conducting any kind of physical or electronic attack on nowhere Staff, property or data centres.

7.5 Social engineering any nowhere Staff, consultants, contractors or associates.

7.6 Conduct vulnerability testing of participating services using anything other than test accounts.

7.7 Violating any laws or breaching any agreements in order to discover vulnerabilities.

8. Personnel Responsible for this Policy

8.1 The Director of Digital and Operations has overall responsibility for the effective operation of this policy and shall be responsible for reviewing this policy to ensure that it meets legal requirements and reflects best practice.

8.2 The Director of Digital and Operations has responsibility for ensuring that any person who may be involved with administration, monitoring, IT security or investigations carried out under this policy receives regular and appropriate training to assist them with these duties.

8.3 It is the responsibility of the Director of Digital and Operations to ensure that all areas under their direction have documented processes that meet minimum standards, are reviewed annually, and are communicated to staff.

8.4 Any exception to the policy must be approved by the Director of Digital and Operations in advance.

8.5 The Security Team will verify compliance to this policy through various methods, including but not limited to, periodic walk-throughs, video monitoring, business tool reports, internal and external audits, and feedback to the Director of Digital and Operations.

9. Breaches of Policy

9.1 Breaches of this policy can be defined as events which could have, or have resulted in, loss or damage to nowhere assets, or an event which is in breach of nowhere security procedures and policies.

9.2 All nowhere Staff and contractors have a responsibility to report security incidents and breaches of this policy as quickly as possible to the Security Team. This obligation also extends to any external organisations contracted to support or access nowhere information systems.

9.3 nowhere will take appropriate measures to remedy any breach of the policy and its associated procedures and guidelines. In the case of Staff then the matter may be dealt with under the disciplinary procedures.

10. Contact Information

10.1 The Security Team can be contacted on security@now-here.com.

Contact Us

To contact our core team, please get in touch at:

enquiries@now-here.com

We look forward to hearing from you.

  • Instagram
  • LinkedIn

Subscribe

Become part of the growing nowhere community around the world.

Sign up to receive our emails giving you access to our latest insights, films and articles.

meeting craft
catalyst
catalytic

are registered trademarks of nowhere group ltd

  • Support
  • Security
  • Trust
  • Status
  • Legal
  • Privacy
  • © nowhere group 2026
Jump to Content