Heads up: Vivid welcomes Nuri users with a special offer. 🚀 Get 1% on top of your crypto for free. Only until 11/12/22. Find out more. 

Coordinated Vulnerability Disclosure Policy


If you think you've spotted a potential security issue with any of our services, we welcome your feedback. Please email us at security@nuri.com or report to us on HackerOne

More details can be found below:



Guidelines


Nuri GmbH believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. If you have discovered a security vulnerability in our systems or in one of our product/services, we appreciate your help in disclosing it to us in a responsible manner.


Please inform us following the procedure described below. We’ll work with you to make sure that we understand the scope of the issue, and that we fully address your concerns. We consider vulnerability disclosures our highest priority and we will try to address any issue as quickly as possible.



Disclosure Policy


  • Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
  • Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own.


Exclusions


While researching, we'd like to ask you to refrain from:


  • Denial of service
  • Spamming
  • Social engineering (including phishing) of Nuri GmbH staff or contractors, or customers
  • Any physical attempts against Nuri GmbH property or data centres
  • Any interaction or unauthorised access to data
  • Missing best practices (we require evidence of a security vulnerability).
  • Use of a known-vulnerable library (without evidence of exploitability).


Out of Scope


  • Reports from automated tools or scans.
  • Missing cookie flags on non-sensitive cookies.
  • Reports of insecure SSL/TLS ciphers (unless you have a working proof of concept, and not just a report from a scanner).
  • Exposure of non-sensitive data on mobile devices
  • Missing security headers which do not lead directly to a vulnerability, including CSP.
  • Our policies on presence/absence of SPF/DMARC/DKIM records.


Third-party bugs


If issues reported to our program affect a third-party library, external project, or another vendor, we reserve the right to forward details of the issue to that party without further discussion with the researcher. We will do our best to coordinate and communicate with researchers through this process, and we will not share your name with third parties without your approval.


Reporting a vulnerability


We accept and discuss vulnerability reports via email at security@nuri.com. Please encrypt your findings using our PGP key to prevent this critical information from falling into the wrong hands. Are you on HackerOne? We accept vulnerability issues on HackerOne as well - https://hackerone.com/nuri.


Reports should include:


  • A Description of the location and potential impact of the vulnerability.
  • A detailed description of the steps required to reproduce the vulnerability. * Proof of concept (POC) scripts, screenshots, and screen captures are all helpful. Please use extreme care to properly label and protect any exploit code.
  • Any technical information and related materials we would need to reproduce the issue.
  • Your name/handle for recognition in our Hall of Fame (optional)
  • Please keep your vulnerability reports current by sending us any new information as it becomes available.


Safe Harbor


Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.


Thank you for helping keep Nuri and our users safe!



Co-funded by the Horizon 2020
programme of all the European Union.

Notices regarding Banking and Cryptocurrency Services

 

Notice pursuant to § 2 Section 10 of the German Banking Act

Nuri GmbH, offers the brokerage of transactions in crypto currencies (being financial instruments pursuant to § 1 para. 1a sentence 2 no. 1 of the German Banking Act (Kreditwesengesetz – KWG)) and in this respect acts exclusively in the name and for the account of the Solarisbank AG. Nuri GmbH is recorded as tied agent of Solarisbank AG within the meaning of § 2 Section 10 of the German Banking Act in the register which is kept by the German Federal Financial Supervisory Authority. The register can be accessed under www.bafin.de. Insofar as investments in other financial instruments are made possible via Nuri GmbH, this is not done in the name or for the account of Solarisbank AG.

 

Warning of risks related to Cryptocurrencies

Trading cryptocurrencies carries high risk and can lead to the total loss of the invested capital. We strongly recommend not to invest more than you can afford to completely lose. Before you start trading cryptocurrencies, please make sure that you fully understand the risks associated. Should you need help we recommend to contact an independent competent person or organisation. Any personal successful investments when trading cryptocurrencies in the past in no case indicate your success in the future. The cryptocurrencies traded on Nuri.com are not suitable for all investors. For further information to the product offering, visit our Support Centre.

 

Notice regarding Nuri Pots

Nuri GmbH provides its services with respect to the purchase and sale of Nuri Pots exclusively for Bankhaus von der Heydt GmbH & Co. KG (BvdH). BvdH is acting as financial commissioner and crypto custodian for the Nuri Pots. The purchase, sale and custody of Nuri Pots is subject to contracts between the user and BvdH. BvdH decides independently on the acceptance of orders and may reject any offers at its own discretion without giving reasons.


Warning of risks related to Nuri Pots

Trading Nuri Pots is associated with risks. Before investing, you are asked to conduct an appropriateness test to assess whether you have the necessary knowledge and experience to adequately evaluate the risks associated with Nuri Pots. Before you start trading Nuri Pots, please make sure that you read and understand the product and risk information provided by BvdH and the issuer.