LegalNaytto
Vulnerability Disclosure Policy
Naytto lets people control their own computers from a browser, so we take reports about its security seriously. If you think you've found a vulnerability, please tell us. This policy says how to report it, what you may test, and what we promise in return.
How to report
Email security@naytto.com. Include what you found, where, the steps to reproduce it and the impact you expect. English is best. Please don't include anyone else's personal data; if you came across some, say so and describe it instead of sending it.
What we promise
- We'll confirm we received your report within 3 business days.
- We'll tell you whether we can reproduce it and what happens next within 10 business days, and keep you updated until it's fixed.
- We aim to fix critical issues within 7 days and others within 90 days, and we'll tell you when a fix is live.
- If you'd like, we'll credit you when we disclose the issue.
- We don't pay bounties.
What you may test
- The Naytto app at app.naytto.com, the website at naytto.com, and the Naytto apps for Mac, Linux and Windows published at naytto.com/download.
- Only with accounts you created and computers you own. Create a separate account for each tenant you want to test isolation between; never access, change or delete another person's data or computer.
What's not allowed
- Denial-of-service, load or volume testing, or anything that degrades the service for others.
- Social engineering or phishing of our staff or customers, and physical attacks.
- Sending spam or abuse through the service, or using the relay to reach third parties.
- Keeping data beyond what you need to show the issue. Delete it once you've reported.
- Testing Cloudflare, Stripe, Google or our other subprocessors themselves; report those to them.
Safe harbor
If you follow this policy in good faith, we consider your research authorized, we won't pursue legal action or report you to law enforcement for it, and we won't treat it as a breach of the Acceptable Use Policy. If someone else takes legal action against you for research that followed this policy, we'll say publicly that it was authorized. If you're unsure whether something is allowed, ask us first at security@naytto.com.
Disclosure
Please give us 90 days, or until a fix is live if that's sooner, before you disclose an issue publicly. We'll agree a date with you and tell affected customers ourselves when their data or computers were at risk.
Last updated: 2026-09-30.