Security
Protecting NeuroCircle and the people who use it is a core part of how we build the platform.
We welcome responsible reports from security researchers, developers, users, and others who identify potential vulnerabilities affecting NeuroCircle.
Report a security vulnerability
If you believe you have discovered a security vulnerability in a NeuroCircle-owned system or service, please report it privately to security@neurocircle.app.
Please include, when available:
- a clear description of the vulnerability;
- the affected product, feature, URL, endpoint, or system;
- steps required to reproduce the issue;
- the potential security or privacy impact;
- relevant screenshots, logs, requests, or technical details; and
- a proof of concept where appropriate.
Please provide enough information for us to understand and reproduce the issue without unnecessarily exposing user information.
Responsible security research
We welcome good-faith security research intended to identify and responsibly disclose vulnerabilities.
When testing NeuroCircle:
- use accounts, devices, and information you own or are authorized to use;
- limit testing to NeuroCircle-owned systems and services;
- avoid accessing another user's account, private information, or content;
- do not intentionally modify, destroy, download, or retain information belonging to others;
- do not perform denial-of-service, traffic flooding, destructive testing, or activity intended to disrupt the service;
- do not use phishing, social engineering, physical attacks, or harassment against NeuroCircle users, employees, contractors, or partners;
- do not introduce malware or intentionally compromise user devices; and
- stop testing and contact us if you encounter sensitive information beyond what is reasonably necessary to demonstrate the issue.
Testing third-party services, infrastructure, applications, or integrations that NeuroCircle does not control is outside the scope of this policy.
Responsible disclosure
Please report potential vulnerabilities privately and allow NeuroCircle a reasonable opportunity to investigate and address the issue before publicly disclosing technical details.
We may contact you for additional information, clarification, or assistance reproducing a finding.
The time required to investigate and resolve a vulnerability may vary depending on its complexity, severity, and affected systems.
What to report
Security reports may include issues involving:
- unauthorized access to accounts or information;
- authentication or authorization vulnerabilities;
- exposure of private or sensitive information;
- privilege escalation;
- injection vulnerabilities;
- cross-site scripting or other exploitable web vulnerabilities;
- security weaknesses that could affect multiple users;
- vulnerabilities that bypass important security or privacy controls; or
- other technical issues that could materially affect the confidentiality, integrity, or availability of NeuroCircle systems or user information.
This list is illustrative, not exhaustive.
If you are uncertain whether something is a security vulnerability, you may still report it to security@neurocircle.app.
Reports that are generally not security vulnerabilities
Issues without a meaningful security impact may be handled as ordinary product bugs.
Examples may include:
- crashes;
- broken features;
- visual or layout problems;
- spelling or display errors;
- accessibility problems;
- isolated performance issues; or
- unexpected product behavior without a security impact.
Report product bugs to bugs@neurocircle.app.
Bug bounty
NeuroCircle does not currently operate a public paid bug bounty program.
Submitting a vulnerability does not guarantee payment, compensation, employment, or another reward.
If NeuroCircle introduces a formal bug bounty program, its scope, eligibility requirements, rewards, and additional terms will be published separately.
Account security
If you believe your NeuroCircle account has been compromised, change your password and review your account security as soon as possible.
For assistance with your account, contact support@neurocircle.app.
Do not send passwords, recovery codes, authentication codes, or other account credentials by email.
Phishing and impersonation
Report suspected phishing, fraudulent NeuroCircle websites, impersonation, malicious communications, or other security-related abuse to security@neurocircle.app.
Official NeuroCircle email addresses use the @neurocircle.app domain.
The official NeuroCircle website is neurocircle.app.
Safety and harmful content
Security vulnerabilities are different from reports involving harmful content or user behavior.
For harassment, threats, exploitation, child-safety concerns, or other safety issues, use NeuroCircle's in-app reporting tools or contact safety@neurocircle.app.
If someone is in immediate danger, contact local emergency services.
Security contacts
Security.txt
NeuroCircle publishes standardized vulnerability-reporting information at:
This provides security researchers and automated tools with a consistent way to locate our security contact and disclosure policy.
Updates
NeuroCircle may update this policy as our products, infrastructure, security practices, and vulnerability disclosure program evolve.
We appreciate responsible reports that help us identify vulnerabilities and strengthen NeuroCircle.