We treat security reports with priority. If you believe you have found a vulnerability in nexcom.media or any property in the Nexcom Media Network, please email security@nexcom.media with a clear description and, where possible, reproduction steps.

We do not currently operate a paid bug-bounty program. We commit to acknowledge reports within five business days, work in good faith with researchers, and credit reporters in our press kit when patches ship — unless the reporter prefers to remain anonymous.

Out of scope: denial-of-service, spam, social engineering, and findings that require physical access to our infrastructure.

This page is the Policy destination referenced by /.well-known/security.txt per RFC 9116.