LegalNaytto

Vulnerability Disclosure Policy

Naytto lets people control their own computers from a browser, so we take reports about its security seriously. If you think you've found a vulnerability, please tell us. This policy says how to report it, what you may test, and what we promise in return.

How to report

Email security@naytto.com. Include what you found, where, the steps to reproduce it and the impact you expect. English is best. Please don't include anyone else's personal data; if you came across some, say so and describe it instead of sending it.

What we promise

What you may test

What's not allowed

Safe harbor

If you follow this policy in good faith, we consider your research authorized, we won't pursue legal action or report you to law enforcement for it, and we won't treat it as a breach of the Acceptable Use Policy. If someone else takes legal action against you for research that followed this policy, we'll say publicly that it was authorized. If you're unsure whether something is allowed, ask us first at security@naytto.com.

Disclosure

Please give us 90 days, or until a fix is live if that's sooner, before you disclose an issue publicly. We'll agree a date with you and tell affected customers ourselves when their data or computers were at risk.

Last updated: 2026-09-30.