Trust Center
Vulnerability disclosure
We want to hear about security issues in Nullgen AI Blocker, and we will not pursue anyone who reports them in good faith.
Last reviewed: September 23, 2026
Scope
This policy covers nullgen.ai and its API, the browser extension for Chrome, Edge, Firefox, and Safari, the Safari Mac app, and the iPhone and iPad app.
Third-party services we use, such as our cloud, payment, email, and error-reporting providers, are out of scope; report issues in those to the provider.
How to report
Email security@nullgen.ai with what you found, where, and how to reproduce it. Screenshots, request and response captures, or a proof of concept help. Encrypt sensitive details if you prefer and tell us how to reply securely.
The same address is published at https://nullgen.ai/.well-known/security.txt in the format described by RFC 9116.
What to expect
We acknowledge reports within three business days and tell you what happens next. We keep you informed while we work on a fix, and we tell you when it ships. If you would like public credit, we will give it; if you prefer to stay anonymous, we will respect that.
Safe harbour
Security research carried out in good faith under this policy is authorized. We will not take or support legal action against you for it, and we treat it as exempt from the restrictions in our Terms of Service on reverse engineering, circumventing protections, and testing our services, provided you: act only within the scope above; avoid privacy violations, data destruction, and service disruption; use only accounts and devices you own or are authorized to test; do not access, modify, or keep data that is not yours beyond what is needed to demonstrate the issue; and give us a reasonable time to fix the issue before disclosing it publicly.
Out of scope
Denial of service and volumetric testing; social engineering or phishing of Nullgen staff or customers; physical attacks; findings that require an already compromised device or browser; reports from automated scanners without a demonstrated impact; and best-practice observations without a security consequence.
Rewards
We do not run a paid bounty program at this time. We credit reporters who want credit, and we answer every report.